I have a problem with GREoIPSec tunnel between Cisco2811 and Catalyst 6509 with 7600-SSC-400 SPA VPN module. I'm running the SPA VPN module in a VRF mode with tunnel protection (12.2(33)SXI1). The IPSec tunnel is up, but I can't access anything through the tunnel. I have also noticed one thing, when I remove the ip nat outside command from the interface which has the crypto engine outside command applied, traffic starts flowing thorough the tunnel without any problem. It seems that you can't do NAT/PAT on the same interface where the crypto engine outside command has been configured.
I have tried to find some workaround to do NAT/PAT and terminate IPSec tunnels on the same interface, bud didn't find anything. If you have any suggestions regarding the problem, your help would be greatly appreciated. Thanks.