data:image/s3,"s3://crabby-images/3f2aa/3f2aa280b5d47630d4c70dfb3892cfb00ba0b834" alt="Arista vEOS Configuration Manual Download Page 99"
Example:
veos(config)#interface Et1
veos(config-if-Et1)#no switchport
veos(config-if-Et1)#ip address 1.0.0.1/24
veos(config-if-Et1)#mtu 1500
8. Apply the IPsec profile to a new tunnel interface. You create the new tunnel interface as part of this step.
You can choose to configure the tunnel as a GRE-over-IPsec tunnel, or a VTI IPsec tunnel.
Example (GRE-over-IPsec): In this example, the new tunnel interface is Tunnel0. The new tunnel interface
is configured to use IPsec, and the tunnel mode is set to GRE. The other end of the tunnel also needs to be
configured as a GRE-over-IPsec tunnel.
veos(config)#interface tunnel0
veos(config-if-Tu0)#ip address 1.0.3.1/24
veos(config-if-Tu0)#tunnel mode gre
veos(config-if-Tu0)#mtu 1394
veos(config-if-Tu0)#tunnel source 1.0.0.1
veos(config-if-Tu0)#tunnel destination 1.0.0.2
veos(config-if-Tu0)#tunnel ipsec profile vrouter
Example (VTI IPsec): To configure a VTI IPsec tunnel, you need to set the tunnel mode to tunnel mode
ipsec. The other tunnel element settings are the same as the settings for GRE-over-IPsec.
veos(config)#interface tunnel0
veos(config-if-Tu0)#ip address 1.0.3.1/24
veos(config-if-Tu0)#tunnel mode ipsec
veos(config-if-Tu0)#mtu 1394
veos(config-if-Tu0)#tunnel source 1.0.0.1
veos(config-if-Tu0)#tunnel destination 1.0.0.2
veos(config-if-Tu0)#tunnel ipsec profile vrouter
Optional Steps
To move the tunnel interface to a different VRF, complete step 9. To achieve high throughput, complete step
10.
9. Create the GRE-over-IPsec tunnel interface in a VRF using the
vrf forwarding
command. If a VRF is
needed, create one then create and configure the GRE tunnel interface. If tunnels in different VRFs need to
share the IPsec connection, configure the same tunnel source, destination, IPsec profile, and a unique tunnel
key for each tunnel.
Note: If tunnels in different VRFs need to share the IPsec connection, specify the same source,
destination, and IPsec profile.
Example:
veos(config)#vrf definition red
veos(config-vrf-red)#rd 1:3
veos(config-vrf-red)#interface tunnel0
veos(config-if-Tu0)#tunnel key 100
veos(config-if-Tu0)#vrf forwarding red
veos(config-if-Tu0)#ip address 1.0.3.1/24
veos(config-if-Tu0)#mtu 1394
veos(config-if-Tu0)#tunnel source 1.0.0.1
veos(config-if-Tu0)#tunnel destination 1.0.0.2
veos(config-if-Tu0)#tunnel key 100
veos(config-if-Tu0)#tunnel ipsec profile vrouter
veos(config)#vrf definition blue
veos(config-vrf-blue)#rd 1:4
veos(config-vrf-blue)#interface tunnel1
veos(config-if-Tu1)#tunnel key 200
99
IPsec Support
Summary of Contents for vEOS
Page 6: ......
Page 12: ......
Page 60: ......
Page 72: ......
Page 77: ...7 Select the default network 8 Complete the launch process 77 Server Requirements ...
Page 94: ...Figure 17 Linux SRIOV PCI Passthrough based Deployment vEOS Router Configuration Guide 94 ...
Page 124: ......
Page 128: ......