Help on IPSec to MPLS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-13-2005 03:57 PM - edited 02-21-2020 01:32 PM
I've configured an IPSec aggregator on a 7200 using isakmp profiles that map to a particular VRF. It works fine when the remote end is also using profiles, however I get an "invalid proxy IDs" after phase 1 when the other end is a VPN concentrator or an IOS based that does not use profiles. I'd appreciate any inputs on this.
- Labels:
-
IPSEC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-14-2005 09:29 AM
You should be able to make this setup work w/o using profiles on the remote end. Indeed the type of CPE does not even matter. Please compare your config to the sample config I am attaching here.
thanx
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-14-2005 09:31 AM
Sorry forgot to attach.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-14-2005 09:40 PM
Hi Haseeb,
This issue has been resolved. It was an overlook on a mismatched mask on the proxies (or traffic that needs to be tunneled).
I also found the documentation you attached helpful. Thanks for the reply and help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-31-2005 01:02 AM
I am just facing a issuse.How can I use VRF awared IPSec for dynamic peers for PE agressived.
In a word ,how to map some dynamic ipsec to different VFP .
Thanks!
