Edificer wrote: » It all turned out good today I actually tested on our live-production, there was downtime for no more than 3 minutes but I had clearance. On remote Endpoint I created the tunnel-groups, and added another IP in the existing crypto maps. When switching Main over to the new IP the vpn only came up after the clear crypto ipsec/isakmp sa command. I'm not sure if I am following guidelines for this. I will research and look for the proper procedures regarding a change of public IP on Main ASA. I guess when they did this last time the command 'default originate' or something similar that caused the Endpoint to be the initiator was the culprit.