cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
447
Views
0
Helpful
1
Replies

Does PfRv3 work with FlexVPN Virtual-Access interface???

hello, we are going through design possibilities for a WAN technology refresh and have come up against a combination which doesn't seem to work. Not sure if it's a bug, or we're doing it wrong or it's just simply not supported. There doesn't seem to be any information available.

We configure the PfRv3 command "domain {name} path {name}" on the WAN facing interface.  This works for a static Tunnel interface but the problem we see is on a hub site with dynamic tunnels. The command seems incompatible at the hub router configured for dynamic tunnel i.e. Virtual-Template cloning to Virtual-Access.

Have tried the command directly on the Virtual-Template and also pushing it using AAA attribute but neither seems to work.

Hoping someone can provide some guidance. Thanks in advance,

Graeme

NB: crossposted with "WAN, Routing and Switching", not sure which is the best forum https://supportforums.cisco.com/discussion/12514241/does-pfrv3-work-flexvpn-virtual-access-interface

1 Reply 1

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Graeme, 

 

The info I found, back from 2014, is that PFRv3 does not support dynamic interfaces (VAs included). 

I'm not aware of any changes in that regard, but you might want to contact your SE to check if it's on the roadmap. 

M.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: