13 messages in net.nether.puck.cisco-nsp[c-nsp] RRI on dynamic cryptomap
FromSent OnAttachments
Yu-lin ChangJan 11, 2005 4:28 am 
McCallum, RobertJan 11, 2005 4:38 am 
Joe ShenJan 11, 2005 4:49 am 
Yu-lin ChangJan 11, 2005 5:05 am 
Yu-lin ChangJan 11, 2005 5:08 am 
Joe ShenJan 11, 2005 5:36 am 
McCallum, RobertJan 11, 2005 5:41 am 
CEW CEWJan 11, 2005 9:16 am 
Michael K. SmithJan 11, 2005 4:03 pm 
Gert DoeringJan 11, 2005 4:21 pm 
Michael K. SmithJan 11, 2005 4:23 pm 
Gert DoeringJan 11, 2005 4:27 pm 
Michael SmithJan 11, 2005 5:48 pm 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:[c-nsp] RRI on dynamic cryptomap Actions...
From:CEW CEW (cew@yahoo.com)
Date:Jan 11, 2005 9:16:44 am
List:net.nether.puck.cisco-nsp

Hi..

We are using vrf aware IPsec feature on a 7206VXR running 12.3.11T2. A dynamic cryptomap with reverse route injection (RRI) is also configured.

When a remote VPN client connects to the 7206VXR, a host route is created dynamically using RRI. However, when the client disconnects, the host route remains in the routing table. Clearing the routing table doesn't help as the route will re-appear in the routing table again. My understanding is that the host routes should be removed after the client disconnects from the 7206 VXR.

Any idea or comments will be greatly appreciated.

Thanks ! CEW