cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1001
Views
0
Helpful
3
Replies

How best to disable GETVPN

ktwaddell
Level 1
Level 1

Hi,

 

Been a long time since I've posted on here, but new to GETVPN, been asked to diabled fully without any down time, so looks like all GM have a open fail policy and no local ACLs.

 

what would you good people suggest as good way to allow traffic just to pass over the MPLS as normal not use the GETVPN?

 

Thanks in advance

Kevin

3 Replies 3

Hi,
I'm not sure it's possible to do without an interruption to service. Ultimately you'll need to disable encryption on all of the interfaces.

E.g
interface GigabitEthernet 0/0
no crypto map GET_MAP

Hi,

 

Currently my options are

1) Deny ip any any on KS gdoi ACL (wait a week to see if any fallout, then safety remove config on GMs)

 

2) Remove all GM peer IP addresses on KSs

 

3)on GMs remove VPN map command from interfaces as you suggested.

 

Thanks

Kev 

 

Adam Hinchliff
Level 1
Level 1

Did you ever make progress with this? 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: