We help IT Professionals succeed at work.
Get Started

Router-to-Router IPSec VPN with one router in VRF

DScouser
DScouser asked
on
1,069 Views
Last Modified: 2012-05-12
Hi,

I have a simple lab setup with 2 x 7200 routers.  Both routers connected together via Fe0/0
RouterA(Fe0/0)------(Fe0/0)RouterB

All Router A interfaces are in a VRF

RouterA Lo0=10.0.0.1
RouterB Lo0=10.0.0.2

Setup static routers on each router to the opposite Lo0 address

All pings working OK (Pretty Simple)

No I want to setup an IPSec tunnel between the two Fe interfaces and encrypt traffic when pinging between the two Lo0 addresses.

Is there any specific configuration I need on RouterA (VRF) to establish the IPSec tunnel?  All works OK without using VRF on RouterA but cannot establish the tunnel when RouterA is in VRF

Below are the configurations with no VRF on RouterA, this works OK...

RouterA

interface Lo0
 ip address 10.0.0.1 255.255.255.255

crypto isakmp policy 1
 encr aes
 authentication pre-share
 group 2

crypto isakmp key test address 192.168.0.2 no-xauth

crypto ipsec transform-set A esp-aes 256 esp-sha-hmac

crypto map IPSEC local-address fa0/0

crypto map IPSEC 10 ipsec-isakmp
 set peer 192.168.0.2
 set transform-set A
 match address acl

interface fastethernet 0/0
 ip address 192.168.0.1 255.255.255.252
 crypto map IPSEC

ip access-list extended acl
 permit ip host 10.0.0.1 host 10.0.0.2

=====

RouterB

interface Lo0
 ip address 10.0.0.2 255.255.255.255

crypto isakmp policy 1
 encr aes
 authentication pre-share
 group 2

crypto isakmp key test address 192.168.0.1 no-xauth

crypto ipsec transform-set A esp-aes 256 esp-sha-hmac

crypto map IPSEC local-address fa0/0

crypto map IPSEC 10 ipsec-isakmp
 set peer 192.168.0.1
 set transform-set A
 match address acl

interface fastethernet 0/0
 ip address 192.168.0.2 255.255.255.252
 crypto map IPSEC

ip access-list extended acl
 permit ip host 10.0.0.2 host 10.0.0.1

So when I add the interfaces on RouterA to a VRF, the IPSec VPN does not establish, I get various errors but cannot seem to find a resolution.  Just wondering if I am missing something on the config

Thanks in advance

Ste
Comment
Watch Question
Commented:
This problem has been solved!
Unlock 1 Answer and 2 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE