cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1550
Views
10
Helpful
4
Replies

Subnet Mask for VTI Interface IP for route-based VPN with Mocrosoft Azure

zobaarul
Level 1
Level 1

Hi all,

I am trying to configure a route-based VPN with Microsoft Azure. I was reading the document in the link below:

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/vpn/asa-97-vpn-config/vpn-vti.pdf

 

In this document, VTI interface IP has been set with a /31 subnet mask. From azure portal, a suggested configuration for on-premises device can be generated which also suggest to set the VTI interface IP with a /31 subnet. I tried to google it but could not find anything definitive.

Could someone explain why /31 subnet mask is suggested here?

 

Thanks in advance and apologies if similar discussion was already here before that I could not find.

 

1 Accepted Solution

Accepted Solutions

Yes anything including 169.x subnet and you can use the mask which you prefer.


*** Please remember to rate useful posts

View solution in original post

4 Replies 4

To avoid wasting IPs because the this subnet is used only between VTI
tunnel endpoints for routing.

Thanks for your reply.

So its not mandatory or anything. And I can use any subnet mask I prefer?

Yes anything including 169.x subnet and you can use the mask which you prefer.


*** Please remember to rate useful posts

Thanks again