cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
764
Views
10
Helpful
3
Replies

Secondary IP for IPsec

MrBeginner
Spotlight
Spotlight

Hi,

I would like to ask about secondary IP to use GRE over IPsec. our current network using GRE over IPsec but we are apply the IPsec profile in Physical WAN interface. Now i want to create another IPsec tunnel for other branch. I will plan to create secondary WAN IP for second IPsec tunnel to communicate new branch. I will apply ipsec profile to VTI or GRE tunnel interface of secondary IP address. is it possible ? it will conflict previous ipsec profile ?

3 Replies 3

@MrBeginner you could use a loopback interface and specify this as the tunnel source of the VTI, it wouldn't conflict.

Failing that you can use the same IP address as the source for a policy based and route based VPN.

 

 

 

 

Hi , 

I just want to do below diagram. I will not use same IP address as source but same physical interface. I worry it will conflict.

Secondary.jpg

@MrBeginner it shouldn't conflict if you've specified the policy based VPN crypto ACL correctly. Provide your configuration if you want further analysis