cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1042
Views
40
Helpful
2
Replies

L2L vpns on ISR4331 - how to hairpin the traffic

mihai.vasc
Level 1
Level 1

Hello all,

There are two L2L vpns to 2 different partners configured on the same Cisco ISR4331 router. Now, beside the other traffic (to the lan of ISR4331), the 2 partners needs to communicate to each other like PartnerA -L2L->  ISR4331 -L2L-> PartnerB. basically the traffic coming over one L2L vpn to be "hairpined"  (on the same physical interface) to the other L2L vpn.

There is no NAT configured on the ISR4331 router for none of the vpns.

I know on ASA there was a command same-security-traffic permit intra-interface... Is there something similar for ISR routers??? Or anything else to make this setup working?

Thanks and best regards,

2 Replies 2

nice Question, 
try 
config two VTI
VTI-1 receive packet form the L2L Site 1 
VTI-2 send the packet toward the L2L Site 2 
note:- config the IPSec profile under the VTI after check the solution is OK.
hope this work.

Hi, yes, that it should work for sure, but unfortunately I cannot use VTI for these L2L vpn. Remote ends are not under my management and VTI solution is not an options.

Both L2L are using crypto map on the same interface on ISR4331.

thanks anyway

Review Cisco Networking for a $25 gift card