cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
468
Views
0
Helpful
2
Replies

Best Sol'n for P2P IPSEC w/ Cat6500 VPN SPA

mchoo2005
Level 1
Level 1

Hi,

Can anyone tell me the best solution for IPSEC encryption over Point-to-point Ethernet link b/w two Cat6500 with VPN SPA? At first I though we could use VTI, but learned the hard way that VTI is not supported on Cat6500/Cisco7600 (if only we read the VTI SRND, it would've saved a bit of headache! :( ).

Thanks muchly for any pointers...

Cheers

2 Replies 2

b.hsu
Level 5
Level 5

Payload Compression Protocol. This is a compression protocol supplied with the Cisco IOS software code on which the FWSM IPSec implementation is based. The FWSM does not support the PCP protocol.

ajagadee
Cisco Employee
Cisco Employee

Michael,

Yes, you are correct. VTI is not supported in IPSEC VPN SPA on 6500. But, is supported on the 7600 with 12.2(33)SRA release. Please refer the below URL for details.

http://www.cisco.com/en/US/products/hw/routers/ps368/module_installation_and_configuration_guides_chapter09186a00804d35a6.html

In your case, if you want dynamic unicast or multicast routing protocols over the tunnel, then GRE Over IPSEC is the way. Configuration Guide in the below URL:

http://www.cisco.com/en/US/products/hw/switches/ps708/module_installation_and_configuration_guides_chapter09186a00805f3812.html#wp1130644

I hope it helps.

Regards,

Arul

Review Cisco Networking for a $25 gift card