[afnog] MPLS - IPsec tunnel between a PE and CE

Mark Tinka mtinka at globaltransit.net
Sat Oct 15 19:09:51 UTC 2011


On Sunday, October 16, 2011 02:52:52 AM Wakwa Nduati wrote:

> Unfortunately I do not have ISC and this sounds like the
> right solution for my client.

You don't need ISC; that's just some fancy Cisco GUI tool to 
make routers look dumb.

What you're looking for is VRF-Aware IPSec. Here's a link 
that goes into it, ignoring fancy tools:

http://www.cisco.com/en/US/docs/ios/ios_xe/sec_secure_connectivity/configuration/guide/sec_vrf_aware_ipsec_xe.html


Note, I haven't used this before, but looks pretty straight 
forward.

Cheers,

Mark.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: This is a digitally signed message part.
URL: <http://afnog.org/pipermail/afnog/attachments/20111016/3a88aecc/attachment.pgp>


More information about the afnog mailing list