Thanks for the response harbor235, but I think you misunderstand what I am doing.
On a VTI, you don't use an access list to characterize traffic, or a crypto map. In this particular setup, I have no crypto map at all. The traffic that gets encrypted depends on what is being routed out the virtual tunnel interface. This all works very well. Unfortunately, ACLs applied to the virtual tunnel interface are not doing anything at all.
Main Topics
Browse All Topics





by: harbor235Posted on 2009-06-04 at 08:56:03ID: 24548366
ACLs the characterize what traffic traverses the VPN tunnel are configured in the crypto map.
ACLs that filter traffic from moving through the device are added to physical interfaces.
harbor235 ;}