cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
255
Views
10
Helpful
3
Replies

Secondary IP for IPsec

MrBeginner
Enthusiast
Enthusiast

Hi,

I would like to ask about secondary IP to use GRE over IPsec. our current network using GRE over IPsec but we are apply the IPsec profile in Physical WAN interface. Now i want to create another IPsec tunnel for other branch. I will plan to create secondary WAN IP for second IPsec tunnel to communicate new branch. I will apply ipsec profile to VTI or GRE tunnel interface of secondary IP address. is it possible ? it will conflict previous ipsec profile ?

3 Replies 3

Rob Ingram
VIP Expert VIP Expert
VIP Expert

@MrBeginner you could use a loopback interface and specify this as the tunnel source of the VTI, it wouldn't conflict.

Failing that you can use the same IP address as the source for a policy based and route based VPN.

 

 

 

 

Hi , 

I just want to do below diagram. I will not use same IP address as source but same physical interface. I worry it will conflict.

Secondary.jpg

@MrBeginner it shouldn't conflict if you've specified the policy based VPN crypto ACL correctly. Provide your configuration if you want further analysis

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers