[c-nsp] IPSec crypto map on MPLS enabled interface?
Ray Burkholder
ray at oneunified.net
Thu Mar 18 07:31:31 EDT 2010
>
> I got around to testing this, and I can't make it work. It seems VTI
> doesn't use GRE, and I can't figure out how to make it. Since the other
> end (not under our control) uses IP-in-GRE-in-IPSec I need the GRE
> part.
>
> Furthermore, the setup has both the "inner" (tunnel) and "outer" (IPSec
> source) in VRFs. When I try to set a VRF in the ISAKMP profile, I get
> the following error in defining the IPSec profile:
>
This vrf-lite solution may help somewhat with your inner / outer vrf stuff.
When throwing MPLS in, I'm not sure how it will react.
http://www.oneunified.net/blog/Cisco/vrflite.article
--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.
More information about the cisco-nsp
mailing list