Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ability for IPSEC ipip tunnel interfaces to be unnumbered

    Scheduled Pinned Locked Moved TNSR
    2 Posts 2 Posters 554 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mcwoody
      last edited by

      Hi

      I am wondering if there is a way without dropping out to tnsr to vppctl to set ipip<x> tunnel to be unnumbered and use the DPDK interface to forward traffic. eg:

      set interface unnumbered ipip0 use VirtualFunctionEthernet0/X/0
      

      Not all ipsec tunnels are route based with a seperate ip tunnel transport for endpoints. In addition to this, setting a route for a tunnel from the docs you are only able to specify and ip not a interface eg:
      if ipip tunnel is setup src 172.10.40.1 dst 167.71.50.1

      
      ip route add 192.168.2.0/24 via 167.71.50.1  ipip0
      
      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Currently the only supported IPsec method is routed IPsec as described in the docs. Policy-based tunnels are something we are looking to add, but there is no ETA.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 1
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.