[c-nsp] IPsec on IOS-XR?

Curtis Piehler cpiehler2 at gmail.com
Wed Oct 26 08:26:51 EDT 2016


You are better off buying an ASR1000.   They are designed to do ipsec at
near line rate

On Oct 26, 2016 8:13 AM, "Hank Nussbacher" <hank at efes.iucc.ac.il> wrote:

I am following the IPsec example here:
http://www.cisco.com/c/en/us/support/docs/ip/generic-
routing-encapsulation-gre/9221-quicktip.html
and have managed to alter the syntax to fit with IOS-XR but when I get
to crypto map commands:

*crypto map myvpn 10 ipsec-isakmp set peer 192.168.2.2 set transform-set
to_fred match address 101 *

I cannot find any comparable command syntax in IOS-XR:
RP/0/RSP0/CPU0:petach-tikva-gp(config)#crypto map VPN 15 gdoi
?
  fail-close  Specify a fail-close ACL.
  interface   Enable crypto map on an interface
  ipsec-node  Set the ipsec node on this crypto map
  match       Match values.
  set         Set values

What am I missing?

Thanks,
Hank
_______________________________________________
cisco-nsp mailing list  cisco-nsp at puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


More information about the cisco-nsp mailing list