cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1260
Views
7
Helpful
2
Replies

CSCvm78941 - ENH Ability to configure NAT for VTI interface

bcp618
Level 1
Level 1

Has anyone found a better work around than switching to an IPSEC solution? The type of setup I have requires BGP and I can't lose that functionality. These sites need internet access and the only way to include traffic sourced from the VTI and out to the internet is to perform an any,outside global nat to include the VTI.

2 Replies 2

bspencer
Level 1
Level 1

I saw this referenced in another forum/article. The suggested workaround is to set your NAT destination interface to ANY.

nat (if-name, ANY) 

This resolved my issue with VTI tunnels utilizing BGP and I was able to access resources on the other side. 

Thanks for posting this...fixed my issue immediately upon deployment.  Saved me several more hours of work!