40-19
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Chapter40 More About....
More About VPN
Security and VPN Devices
IPSecurity Troubleshooting–Understanding and Using Debug Commands
Field Notices
More about VPN Connections and IPSec Policies
A VPN connection is an association between a router interface and an IPSec
policy. The building block of an IPSec policy is the crypto map. A crypto map
specifies the following: a transform set and other parameters to govern
encryption, the identity of one or more peers, and an IPSec rule that specifies
which traffic will be encrypted. An IPSec policy can contain multiple crypto
maps.
The following diagram shows an interface (ATM 3/1.1) associated with an IPSec
policy. The policy has three crypto maps, each specifying a different peer system.
The ATM 3/1.1 interface is thus associated with three VPN connections.
A crypto map can specify more than one peer for a connection. This may be done
to provide redundancy. The following diagram shows the same interface and
policy, but crypto map CM-3 specifies two peers: Topeka and Lawrence.
88433
ATM3/1.1
Crypto Map 1
Policy 5
Crypto Map 2
Crypto Map 3
Seattle
Chicago
Topeka