Activating an IPsec Profile on a VTI
An IPsec profile is activated by binding it to a virtual tunnel interface (VTI) that
is configured as an IPsec VTI.
You can activate an IPsec profile on a VTI by performing the following task.
- From privileged EXEC mode, enter global configuration mode.
- Enter configuration mode for an IPsec tunnel.
- Set the mode of the tunnel to IPsec.
- Specify the IPsec protection profile for the tunnel.
- Return to privileged EXEC mode.
- Verify that the IPsec profile is attached to the VTI.
The following example shows how to configure a VTI, set the mode of the tunnel to IPsec, and bind an IPsec profile to the VTI.
device# configure terminal device (config)# interface tunnel 1 device(config-tnif-1)# vrf forwarding blue device(config-tnif-1)# tunnel source ethernet 1/1/1 device(config-tnif-1)# tunnel destination 10.2.2.1 device(config-tnif-1)# ip address 11.1.1.1/24 device(config-tnif-1)# tunnel mode ipsec ipv4 device(config-tnif-1)# tunnel protection ipsec profile prof_blue