03-03-2022 11:28 AM
hi,
I have to migrate spoke to hub gre tunnel based network to ikev2 vti tunnels. So right now I am using gre tunnels and in crypto map I have gre traffic as criteria for encryption. Since I cannot have at the same time crypto map on physical interface and ipcec protection profiles on hub I need some kind of hybrid model on hub part so I could migrate in some steps. I've found this document that desribes migration, but not gre tunnel scenario
any ideas?
br
03-03-2022 11:36 AM
https://www.cisco.com/c/en/us/support/docs/security/flexvpn/115727-flexvpn-hard-hub-00.html
make review of this link
03-03-2022 11:45 AM
@DraganSkundric87318 how many VPNs do you have to migrate? Are you able to migrate all the VPNs at the same time?
03-03-2022 12:03 PM
well, few hundered .... so I am investigation some kind of partial/hybrid solution. All at once is last option. So far idea is to make new loopback interface on hub that would be source for new VTIs. That way I could make notalatonce migration .... prepare new tunnels on hub with loopback as source ... change tunnel config on spoke and voila. Have to test this
03-03-2022 12:10 PM
@DraganSkundric87318 OK understood, not a simple migration. Yes, a loop back might be feasible, I've not tested it myself though. Please test and provide feedback on whether it's viable.
Do you have spare hardware you can setup as a new hub? That would be cleaner and less chance of an issue
03-08-2022 10:16 AM
hi,
just to update ... new setup with ikev2 VTI and old setup with ikev1 crypto map works ok on the same interface on HUB. No need to use loopback as new source interface. In my present setup crypto map handles gre traffic, and since VTIs a not GRE they are not handled by crypto map and so far looks ok, I can have old and new setup in paralel and migrade in steps.
br
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide