Configuring an ES Tunnel Interface Between a PE and CE Router
This example shows how to configure an ES tunnel interface between a PE router and a CE router in a Layer 3 VPN. The network topology used in this example is shown in Figure 1.
Figure 1: ES Tunnel Interface (IPsec Tunnel)
To configure this example, you perform the steps in the following sections:
Configuring IPsec on Router PE1
Configure IP Security (IPsec) on Router PE1:
Configuring the Routing Instance Without the Encapsulating Interface
You can configure the routing instance on Router PE1 with or without the encapsulating interface (t3-0/1/3 in this example). The following sections explain how to configure the routing instance without it:
- Configuring the Routing Instance on Router PE1
- Configuring the ES Tunnel Interface on Router PE1
- Configuring the Encapsulating Interface for the ES Tunnel
Configuring the Routing Instance on Router PE1
Configure the routing instance on Router PE1:
Configuring the ES Tunnel Interface on Router PE1
Configure the ES tunnel interface on Router PE1:
Configuring the Encapsulating Interface for the ES Tunnel
For this example, interface t3-0/1/3 is the encapsulating interface for the ES tunnel. Configure interface t3-0/1/3:
Configuring the Routing Instance with the Encapsulating Interface
If the tunnel-encapsulating interface, t3-0/1/3, is also configured under the routing instance, you need to specify the routing instance name under the interface definition. The system uses this routing instance to search for the tunnel destination address for the IPsec tunnel using manual security association.
The following sections explain how to configure the routing instance with the encapsulating interface:
- Configuring the Routing Instance on Router PE1
- Configuring the ES Tunnel Interface on Router PE1
- Configuring the Encapsulating Interface on Router PE1
Configuring the Routing Instance on Router PE1
Configure the routing instance on Router PE1 (including the tunnel encapsulating interface):
Configuring the ES Tunnel Interface on Router PE1
Configure the ES tunnel interface on Router PE1:
Configuring the Encapsulating Interface on Router PE1
Configure the encapsulating interface on Router PE1:
Configuring the ES Tunnel Interface on Router CE1
Configure the ES tunnel interface on Router CE1:
Configuring IPsec on Router CE1
Configure IPsec on Router CE1: