[c-nsp] default routing over ipsec

Gaurav Sabharwal gaurav at inwire.net
Tue Aug 28 02:54:57 EDT 2007


on 08/28/2007 04:51 AM matthew zeier said the following:
> I have a remote office in China that wants to split traffic such that 
> domestic routes go out in the clear to the provider and all other 
> traffic (or essentially, the default route) goes out across an IPSEC tunnel.
> 
> I'm not clear on how to make the latter work - do I specific a default 
> route & next hop?  Or does my crypto map need to include 0.0.0.0/0 ?
One option would be to use a VTI and PBR.

Cheers,
- Gaurav


More information about the cisco-nsp mailing list