Assuming you are using IPSec on an IOS router, you can do this. The router determines what traffic should be handled using the VPN tunnel and what traffic to handle normally with the use of access-lists. The following URL covers the confuration of IPSec and specifically the section titled "Create Crypto Access Lists" should answer your question about how the same interface can handle both encrypted and non-encrypted traffic.
BenefitsDocumentationPrerequisiteImage Download LinksLimitationsSupported PlatformsLicense RequirementsTopologyStep-By-Step ConfigurationConfigure Virtual ServiceActivate the virtual service and configure guest IPsConfiguring UTD (Service Plane)Configurin...
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...