Does the private IP assigned to the tunnel need to be a part of any of the protected networks? For example, 192.168.0.1/24 is a protected network currently being sent over the tunnel, so my tunnel address would be 192.168.0.2? EDIT: OK so I'm going to configure my tunnel with IP 172.16.25.1/32, add it to the crypto map for both local and remote endpoints, and that should do it? I'll have to try testing it out when no one is on
... View more