Using Groups in VPN Tunnels
Has anyone ever had any success using Groups in their Phase2 Selectors when connecting to Third Party Gateways? It seems to me that when you use groups it just creates a single Phase2 Tunnel. So, in doing a tunnel with an ASA I did it as a group and seemed it would intermittently work and then not work. When I looked at the tunnel list in the CLI it only shows a single Phase2 tunnel. In this case it was only a single subnet on my side and then 3 on the other. So, I created 3 Phase2 selectors and all is good.
In another case, connecting with a Checkpoint there were 19 destinations so 19 Phase2 selectors were needed...What really gets messed up is when there are multiples on each side so if I had 2 on my end for the Checkpoint example I would end up needing to create 38 Phase2 selectors.
Has anyone gotten it to work any differently? Is there some CLI parameter that would make it generate multiple Phase2 tunnels off a single selector using groups? I end up just doing a copy/paste to create all the selectors so it isn't terrible but it does suck when I end up needing to make some small change in Phase2 and have to modify each and every selector.
Thanks
Mike
