cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
259
Views
0
Helpful
1
Replies

gdoi - traffic sourced from gm router not encrypted

kst.amand
Level 1
Level 1

Group Member(GM) router in a GDOI environment, is not having it's Netflow traffic encrypted. Netflow is sourced from the Loopback interface which is included in the Key Server ACL.

All other traffic originating from behind the GM router is encrypted.

Any help?

What debug commands might help pin point how this Netflow traffic is being treated, relative to GDOI?

Thanks in advance.

1 Reply 1

paitken
Level 1
Level 1

Keith, netflow export traffic bypasses output features (for speed) and isn't encrypted.

You can work around this by creating a crypto tunnel to the netflow collector, and routing the netflow export through the tunnel.

Review Cisco Networking products for a $25 gift card