Interface VPN Commands
XSR CLI Reference Guide 14-123
• ip multicast-redirect - NativeIPSectunnelsattachedtoVPNinterfaceswillnoteasily
forwardmulticasttrafficmulticastpacketredirectiontothe unicastaddressoftheremote
tunnelendpoint.Refertopage14‐126forthecommanddefinition.
•
ip address ‐DefinesanexplicitIPaddressonthisvirtualinterface.Refertopage5‐151for
thecommanddescription.
•
ip nat source‐Controls NATonpacketsenteringthisVPNport.Refertopage5‐186forthe
commanddescription.
•
ip ripcommands‐ConfiguresRIPoptionsontheVPNinterface.Refertothe“Configuring
theInternetProtocol”onpage 5‐83chapterfordescriptionsofRIPcommands.
•
ip split-horizon‐SetsRIPsplit‐horizonoptionsontheVPNport.Refertopage5‐130for
thecommanddescription.
•
ip unnumbered ‐CreatesanunnumberedVPNinterface.Refertopage5‐166forthe
commanddescription.
•
service-policy‐AttachesapolicymaptoanVPNoutputorinputinterface.Refertopage
14‐127forthecommanddescription.
•
tunnel‐CreatesatunneltoaVPNgateway.Refertopage14‐127forthecommand
description.
SomeVPNconfigurationpropertiesareassociatedwithaspecificnetworkinterfaceorrequire
creationofvirtualnetworkinterfacesthatrepresenttunnels.
ThissectiondefinestheVPN‐relatedsubcommandsprovidedbythe
interface vpncommand.
AVPNinterfaceisaspecialformofavirtualnetworkinterfacethatrepresentsanIPSectunnel
withEZ‐IPSecautomaticconfiguration,L2TP,orPPTPtunnel(s).ItisrequiredtosupportVPN
tunnelswhichhaveIPaddresses.Thesetunnelsshouldnotbeconfusedwithtunnelmodein
IPSec.Atunnel
onaVPNinterfacehasIPaddressesatbothendsandisusedbytherouting
subsystemlikeanyothernetworkinterface.
AVPNinterfacecanbeconfiguredasfollows:
• interface vpn 4 point-to-point
• interface vpn 3 multi-point
Point‐to‐Pointinterfacesareusedwhendefininganoutboundtunneltoanothergateway.This
interfacetype,inconjunctionwiththe
tunnelcommand,issuitedtoinitiatingoutboundtunnels
toothersecuritygatewaysthatsupportdynamicIPaddressassignment.
EachoutboundtunnelisassociatedwithaVPNinterface.Thatinterface,whichcanbeconfigured
intotheroutingprotocols,isconsidereddownuntilthetunnelhasconnectedandanIPaddress
hasbeenobtained
fromtheremoteVPNgateway.
Note: The tunnel command is a sub-command of interface vpn.
Note: Only one tunnel may be defined per point-to-point VPN interface.