Wednesday, February 28, 2018

IPsec phase 2

I need a little help understanding how S2S phase 2 works in a specific situation. Every tunnel I have done before has had specific protected networks specified on both ends and combined using object groups. I am currently working with someone who would like for me to use quad 0s for my network and specify for theirs. The reason being is he wants a smaller amount of phase 2 connections to deal with. I don’t see any issues with this working but my question is this.

If I am using object groups from my end, would this act the same as quad 0s as far as the number of phase 2 connections or would it still create a new connection for each protected network?



No comments:

Post a Comment