Configuration of Traffic to Route over an IPsec Tunnel
RUCKUS ICX 7450 supports dynamic routing of traffic over an IPsec tunnel by using routes learned by way of Routing Information Protocol (RIP) or Open Shortest Path First (OSPF).
Because IPsec tunnels are established by using virtual tunnel interfaces (VTIs), they can plug into the routing protocol infrastructure of a router. IPsec VTIs impact a change in the packet path based on routing metrics or by toggling the link state of the tunnel. VTIs provide termination points for site-to-site IPsec VPN tunnels and allow them to behave like routable interfaces. VTIs simplify the IPsec configuration and enable common routing capabilities to be used because the endpoint is associated with an actual interface.
Using VTIs offers the following advantages:
- IPsec configuration does not require a static mapping of IPsec sessions to a physical interface.
-
Please confirm if this bullet point is meaningful and should remain; in was removed from the NI documentation in the last reviewIPsec VTIs provide protection for remote access.
- IPsec VTIs simplify encapsulation and do not require the use of crypto maps for IPsec.
- Common interface capabilities can be applied to the IPsec tunnel because there is a routable interface at the tunnel endpoint.
- IPsec VTIs support flexibility for the sending and receiving of unicast encrypted traffic on any physical interface.