[c-nsp] IPSec crypto map on MPLS enabled interface?

Peter Rathlev peter at rathlev.dk
Thu Mar 18 08:33:15 EDT 2010


On Thu, 2010-03-18 at 08:31 -0300, Ray Burkholder wrote:
> This vrf-lite solution may help somewhat with your inner / outer vrf stuff.
> When throwing MPLS in, I'm not sure how it will react.
> 
> http://www.oneunified.net/blog/Cisco/vrflite.article

Yeah, that's kind of how we do it now. The inside is full MPLS, but the
outside interface (with the crypto map) is just a VRF-Lite interface.

What I'd like is to have all of this just work inside the router, so the
only external connections are two MPLS links (for redundancy) to our
core.

I guess I'll have to live with what it is now.

-- 
Peter





More information about the cisco-nsp mailing list