Configuration of an IPsec Tunnel

Configuration of an IPsec tunnel includes the configuration of virtual tunnel interfaces (VTIs) at the tunnel endpoints and the configuration of both the IKEv2 and IPsec parameters that are used to establish the tunnel and secure the tunnel traffic.

To configure an IPsec tunnel, you must complete the following tasks at the tunnel endpoints:

  • Configure a virtual tunnel interface and set the mode of the tunnel to ipsec.
  • Configure the following values (when the default values are not acceptable):
    • Global parameters for IKEv2
    • An IKEv2 proposal
    • An IKEv2 policy
    • An IKEv2 authentication proposal
    • An IKEv2 profile
    • An IPsec proposal
    • An IPsec profile
  • Bind the IPsec profile to the VTI by using the tunnel protection ipsec profile command.