<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static route throug dynamic vti in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-route-throug-dynamic-vti/m-p/5255198#M1119257</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/257635"&gt;@andre.baumgarten&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tunnels are dynamically created when traffic flows, making them unsuitable for static routing in the GUI...&lt;/P&gt;
&lt;P&gt;So, from my point of vieuw, this is not a bug but rather a limitation of how dynamic VTIs work. If your final design is already using BGP and working well, I’d recommend&lt;EM&gt; sticking with BGP&lt;/EM&gt; instead of trying to force static routing in a scenario that isn't designed for it.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jan 2025 08:26:21 GMT</pubDate>
    <dc:creator>M02@rt37</dc:creator>
    <dc:date>2025-01-31T08:26:21Z</dc:date>
    <item>
      <title>Static route throug dynamic vti</title>
      <link>https://community.cisco.com/t5/network-security/static-route-throug-dynamic-vti/m-p/5255174#M1119254</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;i want to build a Hub-Spoke Topology with dynamic VTIs. The final design is using BGP which is working perfectly. For testing i wanted to set a static route from HUB (with dyn vti) to Spoke. But i cannot select the dyn VTIinterface in the routing GUI. The interface is there and it is shown on cli. BGP is also working, i only cannot select it for static routing. Is it a bug or a feature ;-)?&lt;/P&gt;
&lt;P&gt;thx for feedback.&lt;/P&gt;
&lt;P&gt;Andre&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 07:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-throug-dynamic-vti/m-p/5255174#M1119254</guid>
      <dc:creator>andre.baumgarten</dc:creator>
      <dc:date>2025-01-31T07:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Static route throug dynamic vti</title>
      <link>https://community.cisco.com/t5/network-security/static-route-throug-dynamic-vti/m-p/5255198#M1119257</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/257635"&gt;@andre.baumgarten&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tunnels are dynamically created when traffic flows, making them unsuitable for static routing in the GUI...&lt;/P&gt;
&lt;P&gt;So, from my point of vieuw, this is not a bug but rather a limitation of how dynamic VTIs work. If your final design is already using BGP and working well, I’d recommend&lt;EM&gt; sticking with BGP&lt;/EM&gt; instead of trying to force static routing in a scenario that isn't designed for it.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 08:26:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-throug-dynamic-vti/m-p/5255198#M1119257</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2025-01-31T08:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Static route throug dynamic vti</title>
      <link>https://community.cisco.com/t5/network-security/static-route-throug-dynamic-vti/m-p/5255204#M1119258</link>
      <description>&lt;P&gt;Let me check this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for waiting&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 10:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-throug-dynamic-vti/m-p/5255204#M1119258</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-31T10:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Static route throug dynamic vti</title>
      <link>https://community.cisco.com/t5/network-security/static-route-throug-dynamic-vti/m-p/5255214#M1119259</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Dynamic Virtual Tunnel Interfaces (VTIs) are designed to work with dynamic routing protocols like BGP, rather than static routes. In a Hub-Spoke topology with dynamic VTIs, the inability to select the dynamic VTI interface for static routing in the GUI is likely by design, not a bug.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Dynamic VTIs are created on-demand and are not persistent interfaces&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;This makes them unsuitable for static routing, which requires a stable, always-present interface&lt;/SPAN&gt;, The hub uses a virtual template for dynamic instantiation of IPsec interfaces. Each VPN session generates a unique virtual access interface, making it impractical to configure static routes for these temporary interfaces. &lt;A href="https://docs.defenseorchestrator.com/cdfmc/c_dynamic-vti.html" target="_self"&gt;Here is the link&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you need to test connectivity without using BGP, consider these options.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Use IKEv2 to push routes: Configure the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;route set interface&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;command in your IKEv2 authorization policy to advertise routes over the VTI&lt;/SPAN&gt; &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa919/configuration/vpn/asa-919-vpn-config/vpn-vti.html" target="_self"&gt;Here&lt;/A&gt; and &lt;A href="https://community.cisco.com/t5/vpn/dynamic-vti-can-i-use-static-routes-over-the-tunnel/td-p/4517911" target="_self"&gt;Here&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN class=""&gt;Use a loopback interface: Create a loopback interface with the IP address you want to use for the tunnel, then use&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ip unnumbered&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;on the virtual template to borrow this IP&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;You might be able to create a static route to this loopback&lt;/SPAN&gt; &lt;A href="https://networklessons.com/vpn/flexvpn-hub-and-spoke" target="_self"&gt;Here&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For testing purposes only, you could configure a static VTI on the hub instead of a dynamic VTI, which would allow you to set static routes &lt;A href="https://docs.defenseorchestrator.com/cdfmc/t_configure_endpoints_hub_spoke_topology.html" target="_self"&gt;Here&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 09:28:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-throug-dynamic-vti/m-p/5255214#M1119259</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-01-31T09:28:57Z</dc:date>
    </item>
  </channel>
</rss>

