In a group VPN topology, you have three members A, B. and C. You want A lo communicate with B using a different encryption key from the one it uses to communicate with C.
How do you achieve this?
A.
You put A, B, and C in three different groups
B.
You put A, B, and C in the same group, but you define a different match-policy for communication between A and B and for communication between A and C.
C.
You define a different SA and a different match-policy for communication between A and B and for communication between A and C.
D.
In a group VPN, all members of a group must use the same key to communicate with each other.
should this be D?
I have the same idea. C