virtual tunnel interfaces / crypto maps

virtual tunnel interfaces / crypto maps

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
virtual tunnel interfaces / crypto maps GT 06-11-2008
Posted by GT on June 11, 2008, 12:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
dear all, wanted to see if i could get any comments on the issues
around the concept of 'virtual tunnel interfaces' as a method of
setting up ipsec vpn's

as i have (hopefully correctly) read, there is advantage to be gained
from using VTI's instead of using 'crypto maps' applied to an
interface on account of being applied 'interface-centric' capability
such as dynamic routing, QOS etc.

one most salient question would be whether they provide equivalent
capability to the 'dynamic crypto map;' to support windows VPN
clients ? - reverse route injection etc.

are there issues of coexsitence such that a router provide ipsec
encryption to one site, while using a VTI configuration to establish
ipsec vpn with another device ?

help in this gladly received

Graham


Pure Networks
Posted by News Reader on June 11, 2008, 1:18 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
GT wrote:
> dear all, wanted to see if i could get any comments on the issues
> around the concept of 'virtual tunnel interfaces' as a method of
> setting up ipsec vpn's
>
> as i have (hopefully correctly) read, there is advantage to be gained
> from using VTI's instead of using 'crypto maps' applied to an
> interface on account of being applied 'interface-centric' capability
> such as dynamic routing, QOS etc.
>
> one most salient question would be whether they provide equivalent
> capability to the 'dynamic crypto map;' to support windows VPN
> clients ? - reverse route injection etc.
>
> are there issues of coexsitence such that a router provide ipsec
> encryption to one site, while using a VTI configuration to establish
> ipsec vpn with another device ?
>
> help in this gladly received
>
> Graham
>

Some of the following documents may address your questions.

http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6635/prod_white_paper0900aecd803645b5.pdf

http://www.cisco.com/en/US/docs/ios/12_3t/12_3t14/feature/guide/gtIPSctm.pdf

http://www.cisco.com/en/US/technologies/tk583/tk372/technologies_white_paper0900aecd8029d629.pdf


Best Regards,
News Reader

Posted by GT on June 11, 2008, 4:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> GT wrote:
> > dear all, wanted to see if i could get any comments on the issues
> > around the concept of 'virtual tunnel interfaces' as a method of
> > setting up ipsec vpn's
>
> > as i have (hopefully correctly) read, there is advantage to be gained
> > from using VTI's instead of using 'crypto maps' applied to an
> > interface on account of being applied 'interface-centric' capability
> > such as dynamic routing, QOS etc.
>
> > one most salient question would be whether they provide equivalent
> > capability to the 'dynamic crypto map;' to support windows VPN
> > clients ? - reverse route injection etc.
>
> > are there issues of coexsitence such that a router provide ipsec
> > encryption to one site, while using a VTI configuration to establish
> > ipsec vpn with another device ?
>
> > help in this gladly received
>
> > Graham
>
> Some of the following documents may address your questions.
>
> http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6...
>
> http://www.cisco.com/en/US/docs/ios/12_3t/12_3t14/feature/guide/gtIPS...
>
> http://www.cisco.com/en/US/technologies/tk583/tk372/technologies_whit...
>
> Best Regards,
> News Reader- Hide quoted text -
>
> - Show quoted text -

yep - good docs had got one of them

re routing - to quote - "Dynamic routing can be used with SVTIs.
Routing with DVTIs is not supported or recommended. "

does this mean that we can not redistribute the dynamically created
routes for the dynamic peers ?


Similar ThreadsPosted
IPsec Virtual Tunnel Interfaces April 10, 2007, 9:43 am
tunnels and crypto maps March 20, 2006, 1:42 am
Multiple crypto maps on a 3825 router interface February 8, 2007, 12:12 pm
PIX VPN: Selecting dynamic crypto maps based on certificate April 28, 2008, 4:50 am
HSRP virtual IP on a different subnet as physical interfaces July 20, 2005, 5:55 am
cisco VPN ipsec tunnel virtual interface operation detail question July 28, 2006, 2:57 pm
Virtual Tunnel Interface Flapping - Route Redistribution: static->RIP->OSPF July 12, 2007, 2:44 pm
Low latency queueing over Tunnel interfaces August 29, 2006, 10:56 pm
virtual template and virtual access for ADSL circuits April 28, 2005, 3:22 pm
policy-maps? January 5, 2005, 7:45 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map