I am setting up mulitiple phase-2 SA's using 1 VPN tunnel.
Following the ScreenOS cookbook as a refernce (pg 372 -374)
I've set-up almost 100 vpn's in the past. This is the first time I am trying multiple phase-2 SA's using one tunnel.
Its an older fireware verion (6.1.0r2)
I'm running it becuase I can't upgrade to 6.3 during a prodution cycle.
This is the way the cookbook says to set up Phase 1:
set ike p1-proposal "pre-3des-sha-g2-12800" preshare group2 esp 3des sha-1 second 12800
set ike gateway "cisco1" address 10.200.1.1 Main outgoing-interface "ethernet0/2 " preshare "xxx" proposal "pre-g2-3des-sha"
My question is why is the first "set ike p1-proposal" entry necessary if the 2nd entry (setting up the ike gateway) seems to do esentially the same thing...proposal, etc.
Can someone school me on this subject?