Mailing List Archive

VTI VRF-Aware IPSEC Proxy IDs
Hello all.

It has occured to while working with a couple of ISR’s that the Cisco implementation of the proxy ids is made superficially, as in the router usually does not care at all about the proxy ids. Except probably in policy-mode, but I’ve noticed it being disregarded in route-mode

The Quick Mode selectors are usually sent with the WAN IPs or the 0.0.0.0/0 depending on various configuration snippets. I’m not sure the relevancy if VRF-Aware IPSec is used but my assumption is that the invisible ACL “any any” is used, as per documentation.

However, it’s best to know that other vendors will not accept this behavior (such as PAN/Juniper) and it’s best to be aware and not waste 4 hours of time like me ????

Cheers,
_______________________________________________
cisco-nsp mailing list cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
Re: VTI VRF-Aware IPSEC Proxy IDs [ In reply to ]
Hi,

On Tue, Jun 11, 2019 at 12:48:53PM +0000, Andrei Sabau wrote:
> The Quick Mode selectors are usually sent with the WAN IPs or the 0.0.0.0/0 depending on various configuration snippets. I???m not sure the relevancy if VRF-Aware IPSec is used but my assumption is that the invisible ACL ???any any??? is used, as per documentation.
>
> However, it???s best to know that other vendors will not accept this behavior (such as PAN/Juniper) and it???s best to be aware and not waste 4 hours of time like me ????

On Juniper SSG, any/any phase2 SAs is the most convenient you can have :-)

Besides this, welcome to the world of IPSEC interoperability. Whatever
vendor A does, there is a vendor B out there which will not like it.

gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress

Gert Doering - Munich, Germany gert@greenie.muc.de