cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1094
Views
0
Helpful
3
Replies

GETVPN

Rodrigo Gurriti
Level 3
Level 3

Hello,

I have a newbie question about GETVPN, I've done a LAB to check the fictionally and I had a problem on doing VPN tunnel on the KS.

My lab had a switch where i connected a 3 routers ( 1KS and 2 GM) I can get the traffic encrypted in between my 2 GM but when I try to access a loopback on my KS from any of the GM i fail.

I have full routing in between them.

Can the KS participate on the VPN or it can only be a KS

1 Accepted Solution

Accepted Solutions

rahgovin
Level 4
Level 4

Hi,

Only traffic between GMs is encrypted in a GETVPN environment. And unfortunately, a KS cannot act as a GM as of now. You can deny control plane traffic(ping,telnet,ssh,routing updates) to be exempted from encryption so that use them between gms and Ks.

View solution in original post

3 Replies 3

rahgovin
Level 4
Level 4

Hi,

Only traffic between GMs is encrypted in a GETVPN environment. And unfortunately, a KS cannot act as a GM as of now. You can deny control plane traffic(ping,telnet,ssh,routing updates) to be exempted from encryption so that use them between gms and Ks.

Thanks Rahul Govindan,

silly question .... Can the KS play the two roles ? be a KS and GM at the same time?

Hi,

No. It cannot be the KS and GM at the same time. You need 2 different routers for that.