MikeO5422 wrote: » Thanks guys, I believe I found what I was looking for after reading through some documentation. Table 23-2 Special Meanings of Permit and Deny in Crypto Access Lists Applied to Outbound Traffic Match criterion in an ACE containing a permit statement - Halt further evaluation of the packet against the remaining ACEs in the crypto map set, and evaluate the packet security settings against those in the transform sets assigned to the crypto map. After matching the security settings to those in a transform set, the security appliance applies the associated IPsec settings. Typically for outbound traffic, this means that it decrypts, authenticates, and routes the packet.
CaptainJ wrote: » RouteMyPacket, thanks for putting it to a scenario. I would guess since they are part of the same crypto map that the sequence numbers matter. But that would mean traffic coming from peer 2.2.2.2 would never find its way back?