04-14-2025 03:33 AM
Hello Everyone
I have some generic questions regarding the IPsec.
When we use Crypto Map on VPN. How does the Routing table update the protected network? Generally I know how it works, but I wonder if the IP route should be inserted in the routing table by itself. For example, I use RRI (routing reverse injection), and I can see the path in the Routing table. But for another configuration where there is no RRI and the tunnel is working, I do not see the path to the protected network on the other end of the tunnel. Is it a must to see the path in the table, or will the crypto map redirect that traffic to the interface where we have applied the crypto map it??
04-14-2025 09:25 AM - edited 04-14-2025 09:34 AM
@NikoMax RRI is not mandatory, it is typically used when you want to redistribute the VPN routes to other parts of the network, useful if there are multiple exit points in a network.
As long as traffic to the remote destination is routed to the outside interface of the firewall/router where the VPN is configued and assuming the traffic matches the crypto ACL that defines the interesting traffic, then the traffic will be encrypted and routed over the tunnel.
04-18-2025 05:43 AM
If you d9nt use RRI then your VPN use defualt route or static route.
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide