Showing results for 
Search instead for 
Did you mean: 

GETVPN - Can multiple interfaces on the same Group member be in the same GDOI




I have a Group member R1 that is currently registered to two different GETVPN GDOI domains and thus two sets of Key Servers. 


R1 has one interface in GDOI ABC (crypto map ABC) and one interface in GDOI XYZ (crypto-map XYZ).
R2 has one interface in GDOI XYZ (crypto-map XYZ).


GDOI ABC connects the R1 to the rest of a WAN topology and other GM members.

GDOI XYZ connects this R1 router to a router R2 over a backend 1Gb circuit that is a satellite site to this one, which is also registered to the Key Server for GDOI XYZ


I am being tasked with decommissioning the GDOI XYZ domain key servers so need to get the R1 and R2 routers onto the GDOI ABC domain. 


What I am not sure of is whether R1 can have two interfaces with the same crypto-map and would that mean two sets of registration sessions to the ABC Key Server? 


And would R2 be able to reach the GDOI ABC Key Servers through R! prior to registration?


Unfortunately I do not have lab or means to test this theory so wondered if someone out there has done something similar or knows the tech well enough to advise.


Thanks & Regards

2 Replies 2

As I get there are two group,
R1 is member for both "1"&"2",
R2 is member of Only one group "2",
So you want  R2 to also join group "1" while it to have any link to KS of group "2"?
WHY not traffic from R2 will go to R1, this traffic is secure with GDOI of group "2" 
R1 will send the traffic to destination in group "1" using secure with GDOI group "1"
there will be hard work in R1.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers