01-13-2005 03:57 PM - edited 02-21-2020 01:32 PM
I've configured an IPSec aggregator on a 7200 using isakmp profiles that map to a particular VRF. It works fine when the remote end is also using profiles, however I get an "invalid proxy IDs" after phase 1 when the other end is a VPN concentrator or an IOS based that does not use profiles. I'd appreciate any inputs on this.
01-14-2005 09:29 AM
You should be able to make this setup work w/o using profiles on the remote end. Indeed the type of CPE does not even matter. Please compare your config to the sample config I am attaching here.
thanx
01-14-2005 09:31 AM
01-14-2005 09:40 PM
Hi Haseeb,
This issue has been resolved. It was an overlook on a mismatched mask on the proxies (or traffic that needs to be tunneled).
I also found the documentation you attached helpful. Thanks for the reply and help.
03-31-2005 01:02 AM
I am just facing a issuse.How can I use VRF awared IPSec for dynamic peers for PE agressived.
In a word ,how to map some dynamic ipsec to different VFP .
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide