10 Gbps through 6500 SVC-IPSEC-1 with vrf-aware ipsec

Unanswered Question
Apr 19th, 2007
User Badges:

Hi,


I have a customer that has a 6500 with sub720 and FWSM.

We have connected this switch to the Internet with a 10 Gbps interface. We use BGP for this connection. All ingress traffic goes to the outside VLAN of the FWSM. The inside VLAN of the FWSM is part of an ?inside? VRF. This VRF keeps the inside and outside traffic separated.

Now we want to add an WS-SVC-IPSEC-1 module to terminate some site-to-site GRE/IPSEC tunnels directly on the inside VRF. These tunnels do not have to go throught the FWSM. We can do this with VFR-aware IPSEC.

But when I do that I will have to connect the 10 Gbps Internet interface to the IPSEC blade with a ?crypto engine slot? command.

Does that mean that all traffic (encrypted and unencrypted) will have to pass through the IPSEC blade ? Would that be a problem with 10 Gig ?

Do I have any other options ?


Thanks for the advice.


Regards,


Gerard


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
amritpatek Wed, 04/25/2007 - 07:14
User Badges:
  • Silver, 250 points or more

Yes, you will have to connect the 10 Gbps Internet interface to the IPSEC blade with a crypto engine slot command.


vanbon Wed, 04/25/2007 - 10:25
User Badges:

Thanks for the reply.

But is it supported and advisable to connect a 10 gig interface to the IPSEC module ?


Actions

This Discussion