12-03-2008 07:55 AM - edited 02-21-2020 04:03 PM
I want to modify a working IPSev via VTI connection. At the moment i use the following Config for the transform set.
crypto ipsec transform-set VPN-TUNNEL ah-sha-hmac esp-aes 256
Now i want to use the transport mode and altered the config to:
crypto ipsec transform-set VPN-TUNNEL ah-sha-hmac esp-aes 256
mode transport
My problem is, with this modification IPSec doesn't work!
I know that the difference between Transport and Tunnel mode is only observable when the source and destination of the traffic (e.g. Ping) is at the tunnel endpoints.
12-03-2008 11:43 PM
02-10-2009 03:59 AM
I thought VTI only supports tunnel mode.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: