Cisco Systems virtual tunnel interfaces / crypto maps

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
virtual tunnel interfaces / crypto maps GT 06-11-08
Posted by GT on June 11, 2008, 12:23 pm
Please log in for more thread options
dear all, wanted to see if i could get any comments on the issues
around the concept of 'virtual tunnel interfaces' as a method of
setting up ipsec vpn's

as i have (hopefully correctly) read, there is advantage to be gained
from using VTI's instead of using 'crypto maps' applied to an
interface on account of being applied 'interface-centric' capability
such as dynamic routing, QOS etc.

one most salient question would be whether they provide equivalent
capability to the 'dynamic crypto map;' to support windows VPN
clients ? - reverse route injection etc.

are there issues of coexsitence such that a router provide ipsec
encryption to one site, while using a VTI configuration to establish
ipsec vpn with another device ?

help in this gladly received

Graham


Posted by News Reader on June 11, 2008, 1:18 pm
Please log in for more thread options
GT wrote:
> dear all, wanted to see if i could get any comments on the issues
> around the concept of 'virtual tunnel interfaces' as a method of
> setting up ipsec vpn's
>
> as i have (hopefully correctly) read, there is advantage to be gained
> from using VTI's instead of using 'crypto maps' applied to an
> interface on account of being applied 'interface-centric' capability
> such as dynamic routing, QOS etc.
>
> one most salient question would be whether they provide equivalent
> capability to the 'dynamic crypto map;' to support windows VPN
> clients ? - reverse route injection etc.
>
> are there issues of coexsitence such that a router provide ipsec
> encryption to one site, while using a VTI configuration to establish
> ipsec vpn with another device ?
>
> help in this gladly received
>
> Graham
>

Some of the following documents may address your questions.

http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6635/prod_white_paper0900aecd803645b5.pdf

http://www.cisco.com/en/US/docs/ios/12_3t/12_3t14/feature/guide/gtIPSctm.pdf

http://www.cisco.com/en/US/technologies/tk583/tk372/technologies_white_paper0900aecd8029d629.pdf


Best Regards,
News Reader

Posted by GT on June 11, 2008, 4:37 pm
Please log in for more thread options
> GT wrote:
> > dear all, wanted to see if i could get any comments on the issues
> > around the concept of 'virtual tunnel interfaces' as a method of
> > setting up ipsec vpn's
>
> > as i have (hopefully correctly) read, there is advantage to be gained
> > from using VTI's instead of using 'crypto maps' applied to an
> > interface on account of being applied 'interface-centric' capability
> > such as dynamic routing, QOS etc.
>
> > one most salient question would be whether they provide equivalent
> > capability to the 'dynamic crypto map;' to support windows VPN
> > clients ? - reverse route injection etc.
>
> > are there issues of coexsitence such that a router provide ipsec
> > encryption to one site, while using a VTI configuration to establish
> > ipsec vpn with another device ?
>
> > help in this gladly received
>
> > Graham
>
> Some of the following documents may address your questions.
>
> http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6...
>
> http://www.cisco.com/en/US/docs/ios/12_3t/12_3t14/feature/guide/gtIPS...
>
> http://www.cisco.com/en/US/technologies/tk583/tk372/technologies_whit...
>
> Best Regards,
> News Reader- Hide quoted text -
>
> - Show quoted text -

yep - good docs had got one of them

re routing - to quote - "Dynamic routing can be used with SVTIs.
Routing with DVTIs is not supported or recommended. "

does this mean that we can not redistribute the dynamically created
routes for the dynamic peers ?


Similar ThreadsPosted
virtual tunnel interfaces / crypto maps June 11, 2008, 12:23 pm
IPsec Virtual Tunnel Interfaces April 10, 2007, 9:43 am
tunnels and crypto maps March 20, 2006, 1:42 am
Help with understanding Transform Sets and Crypto Maps... (PIX/ASA) December 4, 2008, 10:42 am
Multiple crypto maps on a 3825 router interface February 8, 2007, 12:12 pm
PIX VPN: Selecting dynamic crypto maps based on certificate April 28, 2008, 4:50 am
HSRP virtual IP on a different subnet as physical interfaces July 20, 2005, 5:55 am
cisco VPN ipsec tunnel virtual interface operation detail question July 28, 2006, 2:57 pm
Virtual Tunnel Interface Flapping - Route Redistribution: static->RIP->OSPF July 12, 2007, 2:44 pm
Low latency queueing over Tunnel interfaces August 29, 2006, 10:56 pm
Route-Maps and PIX November 12, 2006, 2:47 am
Route Maps October 9, 2007, 2:00 pm
route-maps (again) May 8, 2008, 11:01 am
Route Maps with HSRP October 19, 2005, 4:45 pm
Question on using route maps. March 3, 2006, 1:10 pm