cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1053
Views
0
Helpful
4
Replies

Help on IPSec to MPLS

omarquez
Level 1
Level 1

I've configured an IPSec aggregator on a 7200 using isakmp profiles that map to a particular VRF. It works fine when the remote end is also using profiles, however I get an "invalid proxy IDs" after phase 1 when the other end is a VPN concentrator or an IOS based that does not use profiles. I'd appreciate any inputs on this.

4 Replies 4

hniazi
Cisco Employee
Cisco Employee

You should be able to make this setup work w/o using profiles on the remote end. Indeed the type of CPE does not even matter. Please compare your config to the sample config I am attaching here.

thanx

hniazi
Cisco Employee
Cisco Employee

Sorry forgot to attach.

Hi Haseeb,

This issue has been resolved. It was an overlook on a mismatched mask on the proxies (or traffic that needs to be tunneled).

I also found the documentation you attached helpful. Thanks for the reply and help.

Not applicable

I am just facing a issuse.How can I use VRF awared IPSec for dynamic peers for PE agressived.

In a word ,how to map some dynamic ipsec to different VFP .

Thanks!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: