12-05-2024 10:52 PM
Hi. I currently have a crypto map applied to a port-channel on my ISR4431 which has a very outdated software version 03.16.04b.S. I want to upgrade it to a newer version, however I noticed that on newer versions crypto maps aren't supported on port-channels: "Currently only GDOI crypto map is supported on tunnel or port-channel interface"
Does anyone have information on which version is the latest that supports crypto maps on port-channels? As migrating to VTIs is not an option.
Thanks in advance.
12-05-2024 11:31 PM
@rramish06 hi,
check this thread.
2911 Router Mitigation 4431 Router Cyrpto Map - Cisco Community
currently recommended version for this router is 17.12.4 or 17.9.5a
Software Download - Cisco Systems
12-06-2024 12:01 AM
M.
12-06-2024 07:13 AM
Hello @rramish06
The ISR 4431 is running Cisco IOS XE software, and the use of crypto maps on port-channels has been deprecated in favor of modern approaches like VTIs.
Virtual Tunnel Interfaces are a more modern and flexible solution for establishing VPN tunnels compared to traditional crypto maps, especially when used with port-channels. With VTIs, you can create a point-to-point VPN tunnel that can be applied to a physical interface or even a logical interface like a port-channel. This eliminates the limitations that come with using crypto maps on port-channels...
12-06-2024 07:35 AM
Greetings!
Offering up a potential modification: have you looked at potentially converting to BDI interfaces? Not sure if the support for crytpo maps is supported but the link aggregation mechanism is similar and comparible with port channels.
hope this helps.
12-06-2024 04:01 PM - edited 12-06-2024 05:00 PM
WARNING:
The router is currently on 3.16.X and there is a possibility of upgrading to 17.12.X (and later). So consider the following:
Please read this: Cisco ISR & ASR 1k Routers: IOS-XE/Firmware Upgrade (Install Mode)
The steps are:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide