Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
stallwoodj
Collaborator
Collaborator
Jump to solution

VTI Numbered to Unnumbered Peer Interop

Hi,

I'm in the process of investigating a conversion from non-CP firewall to VSX virtual firewall.

The current device has lots of unnumbered (route-based) tunnels to third parties with various different vendor firewalls. VSX requires VTI's to have IP addresses.

A quick test between my lab VSX and a standalone CP with an unnumbered VTI (statements such as "set static-route 192.0.2.1/32 nexthop gateway logical vpnt9 on") seems on cursory testing to work.

Has anyone else used numbered VTI's interoperating with remote unnumbered tunnels, is it supported and are there any caveats please?

Thanks!

Jamie

 

1 Solution

Accepted Solutions
Bob_Zimmerman
Authority
Authority

The numbering of VTIs is only locally-significant. Numbered and unnumbered work just fine for passing traffic. You won't be able to talk firewall-to-firewall (since one of the firewalls won't recognize the traffic as being for itself), but that's generally only used for dynamic routing over the VTI.

View solution in original post

3 Replies
PhoneBoy
Admin
Admin

I've never heard of any issues one way or another.

0 Kudos
Bob_Zimmerman
Authority
Authority

The numbering of VTIs is only locally-significant. Numbered and unnumbered work just fine for passing traffic. You won't be able to talk firewall-to-firewall (since one of the firewalls won't recognize the traffic as being for itself), but that's generally only used for dynamic routing over the VTI.

the_rock
Legend
Legend

I seen customers do that before and it does work. Not sure if its officially supported, but works fine.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events