Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > virtual tunnel interfaces / crypto maps

Reply
Thread Tools

virtual tunnel interfaces / crypto maps

 
 
GT
Guest
Posts: n/a
 
      06-11-2008
dear all, wanted to see if i could get any comments on the issues
around the concept of 'virtual tunnel interfaces' as a method of
setting up ipsec vpn's

as i have (hopefully correctly) read, there is advantage to be gained
from using VTI's instead of using 'crypto maps' applied to an
interface on account of being applied 'interface-centric' capability
such as dynamic routing, QOS etc.

one most salient question would be whether they provide equivalent
capability to the 'dynamic crypto map;' to support windows VPN
clients ? - reverse route injection etc.

are there issues of coexsitence such that a router provide ipsec
encryption to one site, while using a VTI configuration to establish
ipsec vpn with another device ?

help in this gladly received

Graham

 
Reply With Quote
 
 
 
 
News Reader
Guest
Posts: n/a
 
      06-11-2008
GT wrote:
> dear all, wanted to see if i could get any comments on the issues
> around the concept of 'virtual tunnel interfaces' as a method of
> setting up ipsec vpn's
>
> as i have (hopefully correctly) read, there is advantage to be gained
> from using VTI's instead of using 'crypto maps' applied to an
> interface on account of being applied 'interface-centric' capability
> such as dynamic routing, QOS etc.
>
> one most salient question would be whether they provide equivalent
> capability to the 'dynamic crypto map;' to support windows VPN
> clients ? - reverse route injection etc.
>
> are there issues of coexsitence such that a router provide ipsec
> encryption to one site, while using a VTI configuration to establish
> ipsec vpn with another device ?
>
> help in this gladly received
>
> Graham
>


Some of the following documents may address your questions.

http://www.cisco.com/en/US/prod/coll...cd803645b5.pdf

http://www.cisco.com/en/US/docs/ios/...e/gtIPSctm.pdf

http://www.cisco.com/en/US/technolog...cd8029d629.pdf


Best Regards,
News Reader
 
Reply With Quote
 
 
 
 
GT
Guest
Posts: n/a
 
      06-11-2008
On Jun 11, 6:18*pm, News Reader <u...@domain.null> wrote:
> GT wrote:
> > dear all, wanted to see if i could get any comments on the issues
> > around the concept of 'virtual tunnel interfaces' as a method of
> > setting up ipsec vpn's

>
> > as i have (hopefully correctly) read, there is advantage to be gained
> > from using VTI's instead of using 'crypto maps' applied to an
> > interface on account of being applied 'interface-centric' capability
> > such as dynamic routing, QOS etc.

>
> > one most salient question would be whether they provide equivalent
> > capability to the 'dynamic crypto map;' to support windows VPN
> > clients ? - reverse route injection etc.

>
> > are there issues of coexsitence such that a router provide ipsec
> > encryption to one site, while using a VTI configuration to establish
> > ipsec vpn with another device ?

>
> > help in this gladly received

>
> > Graham

>
> Some of the following documents may address your questions.
>
> http://www.cisco.com/en/US/prod/coll...537/ps6586/ps6...
>
> http://www.cisco.com/en/US/docs/ios/...re/guide/gtIPS...
>
> http://www.cisco.com/en/US/technolog...hnologies_whit...
>
> Best Regards,
> News Reader- Hide quoted text -
>
> - Show quoted text -


yep - good docs had got one of them

re routing - to quote - "Dynamic routing can be used with SVTIs.
Routing with DVTIs is not supported or recommended. "

does this mean that we can not redistribute the dynamically created
routes for the dynamic peers ?

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IPsec Virtual Tunnel Interfaces Robert Jacobs Cisco 0 04-10-2007 01:43 PM
tunnels and crypto maps Dan Lanciani Cisco 0 03-20-2006 06:42 AM
several crypto maps for one interface, is it possible? B.T. Cisco 1 10-19-2004 08:00 PM
Split Tunnel Blocks http through tunnel but passes http around tunnel a.nonny mouse Cisco 2 09-19-2004 12:10 AM
multiple crypto maps on cisco pix tical Cisco 2 12-02-2003 05:56 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57