QuestionQ20

Site-to-site Virtual Private Networks on Routers and Firewalls

In a FlexVPN hub-and-spoke topology in which spoke-to-spoke tunnels are not permitted, which command is required so that the hub can terminate FlexVPN tunnels?

Explanation

A FlexVPN hub uses a dynamic virtual tunnel interface configured with interface virtual-template. For each incoming spoke-to-hub connection, it creates a corresponding Virtual-Access interface from that template to terminate the tunnel. ip nhrp redirect supports spoke-to-spoke tunnel optimization and is not required when such tunnels are prohibited.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!