> > I got around to testing this, and I can't make it work. It seems VTI > doesn't use GRE, and I can't figure out how to make it. Since the other > end (not under our control) uses IP-in-GRE-in-IPSec I need the GRE > part. > > Furthermore, the setup has both the "inner" (tunnel) and "outer" (IPSec > source) in VRFs. When I try to set a VRF in the ISAKMP profile, I get > the following error in defining the IPSec profile: >
This vrf-lite solution may help somewhat with your inner / outer vrf stuff. When throwing MPLS in, I'm not sure how it will react. http://www.oneunified.net/blog/Cisco/vrflite.article -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
