cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
381
Views
5
Helpful
3
Replies

Site-to-Site VPN

cool rohan
Level 1
Level 1

If you create a site-to-site vpn how many SA are created total some are saying 2 and some are saying 3 which is correct

In phase 1 one sa will created  and in phase 2 two unidirectional sa will be created so there will be total 3 sa or 2 sa ?

I am confused

1 Accepted Solution

Accepted Solutions

Rahul Govindan
VIP Alumni
VIP Alumni

Usually its one phase 1 SA, two phase 2 SA's per crypto ACL. The Phase 2 SA's are usually a pair of inbound and outbound SA's, each with its own SPI (identifier). 

Some terminology may categorize the inbound and outbound phase 2 SA as a single SA, causing the confusion as you mentioned. 

View solution in original post

3 Replies 3

Rahul Govindan
VIP Alumni
VIP Alumni

Usually its one phase 1 SA, two phase 2 SA's per crypto ACL. The Phase 2 SA's are usually a pair of inbound and outbound SA's, each with its own SPI (identifier). 

Some terminology may categorize the inbound and outbound phase 2 SA as a single SA, causing the confusion as you mentioned. 

Little (but relevant) typo: It has to read "two phase 2 SA's per crypto ACE". There could be more than one ACL (one per crypto map), but each ACE within that ACL can generate a pair of SAs.

Karsten, You are right :) Should be crypto ACE or crypto ACL entry/line instead of simply ACL.