Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Bronze

VTI IPSec

Hi,

In general we have installed an analog cameras in many of our branches and remote sites and we want to isolate the business applications traffic from the cameras viewing traffic as the follows:

HQ Links:

- main link: by default all the branch traffic passes through the primary link of that branch and also using the main link at the HQ.

- VTI (1): this line will carry all the traffic when the primary link at the branch failed or the main link is down.

- VTI (2): this line will be used to carry the cameras traffic. HQ cameras viewer watch all the time the cameras at the branches and remote sites, so his/her request should be passed using the VTI (2) and also the reply (upload from the branches and remote sites) should be passed through the remote site backup link and passed through the VTI (2) line.

for the Proider2 VPN network i'm using Virtual Tunnel interface with IP Security (IPSec).

My questiong: is it applicable to configure the branch router for two VTI interfaces; the first one will be the default path when the primary link is down and the second one will carry the cameras viewing traffic all the time.

when the VTI (2) link is down we don't want to backup the cameras viewing traffic to another link.

i attached the network topology diagram.

thanks in advance

1 REPLY
Bronze

VTI IPSec

I forgot to mention that i'm applying HSRP at the branches.

169
Views
0
Helpful
1
Replies
CreatePlease to create content