[c-nsp] IPSec crypto map on MPLS enabled interface?
Peter Rathlev
peter at rathlev.dk
Thu Mar 18 08:33:15 EDT 2010
On Thu, 2010-03-18 at 08:31 -0300, Ray Burkholder wrote:
> This vrf-lite solution may help somewhat with your inner / outer vrf stuff.
> When throwing MPLS in, I'm not sure how it will react.
>
> http://www.oneunified.net/blog/Cisco/vrflite.article
Yeah, that's kind of how we do it now. The inside is full MPLS, but the
outside interface (with the crypto map) is just a VRF-Lite interface.
What I'd like is to have all of this just work inside the router, so the
only external connections are two MPLS links (for redundancy) to our
core.
I guess I'll have to live with what it is now.
--
Peter
More information about the cisco-nsp
mailing list