Hi,
I am trying to implement a site to site vpn between ASR 1K and ASA FW.
On the ASR I am using tunnel mode ipsec ipv4 with Tunnel protection and on the ASA I am using crypto-map.
Is it a valid configuration ?
Thanks,
Koby,
Thanks,
this is cisco TAC engineer answer:
You would like to also know if the tunnel interface with tunnel protection will work with crypto map on ASA.
The answer is that you need to use either:
dVTI – dynamic VTI – in this case the ASR will always ...