[c-nsp] IPSec crypto map on MPLS enabled interface?

Ray Burkholder ray at oneunified.net
Thu Mar 18 07:31:31 EDT 2010


> 
> I got around to testing this, and I can't make it work. It seems VTI
> doesn't use GRE, and I can't figure out how to make it. Since the other
> end (not under our control) uses IP-in-GRE-in-IPSec I need the GRE
> part.
> 
> Furthermore, the setup has both the "inner" (tunnel) and "outer" (IPSec
> source) in VRFs. When I try to set a VRF in the ISAKMP profile, I get
> the following error in defining the IPSec profile:
> 

This vrf-lite solution may help somewhat with your inner / outer vrf stuff.
When throwing MPLS in, I'm not sure how it will react.

http://www.oneunified.net/blog/Cisco/vrflite.article


-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.



More information about the cisco-nsp mailing list