Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Cisco IOS IPsec VTI setup and troubleshooting

From Tech-Wiki


Configure the IPsec Virtual Tunnel Interface (VTI) data plane on Cisco IOS XE and use current verification commands when troubleshooting tunnel establishment and traffic flow.

ⓘ
Validation status
Reviewed against current Cisco IOS XE IPsec Virtual Tunnel Interface documentation on 27 September 2026.
!
IKE configuration is design-specific
The VTI commands below cover the tunnel and IPsec-profile structure. IKE authentication, proposals, keyrings, identities and peer policy must be configured for the target IOS XE release and peer design. Do not copy an unrelated IKE profile or pre-shared key into production.

VTI structure

An IPsec VTI uses a routed tunnel interface associated with an IPsec profile. Current IOS XE documentation supports this model for IPv4 and IPv6.

Define the required transform set according to the approved cryptographic policy for the deployment.

>_Example IPsec transform set
crypto ipsec transform-set VTI-TSET esp-aes 256 esp-sha256-hmac
 mode tunnel

Create an IPsec profile and associate the transform set:

>_Create the IPsec profile
crypto ipsec profile VTI-PROFILE
 set transform-set VTI-TSET

Configure the tunnel interface:

>_Example static VTI
interface Tunnel0
 ip address 192.0.2.1 255.255.255.252
 tunnel source GigabitEthernet0/0
 tunnel destination 203.0.113.2
 tunnel mode ipsec ipv4
 tunnel protection ipsec profile VTI-PROFILE

The peer must be configured with compatible IKE/IPsec parameters and appropriate routing.

Troubleshooting workflow

Start with the routed interface and crypto-session state before enabling debugging.

>_Check interface and routing state
show interfaces Tunnel0
show ip route

Review the overall crypto session and IPsec security associations:

>_Check crypto state
show crypto session
show crypto ipsec sa

For IKEv2 deployments, also review the IKEv2 security association:

>_Check IKEv2 state
show crypto ikev2 sa

For legacy IKEv1 deployments, use the applicable ISAKMP/IKEv1 commands for that platform and release.

What to check

When a VTI does not pass traffic, verify:

  • The tunnel source and destination are reachable outside the VPN.
  • The IKE peer identity and authentication match at both ends.
  • IKE and IPsec algorithms have a compatible proposal.
  • The tunnel interface has the expected line protocol state.
  • Routing sends the protected networks towards the tunnel interface.
  • IPsec packet counters increment for both encapsulation and decapsulation.
  • NAT or policy-based controls are not unexpectedly changing the protected traffic.
  • MTU/MSS behaviour is appropriate for the additional IPsec overhead.
✓
Use counters before debug
show crypto session and show crypto ipsec sa often identify whether the problem is IKE establishment, IPsec SA creation, routing or one-way traffic without the operational impact of verbose debugging.

Migration from crypto maps

Cisco documents migration options from policy-based crypto maps to VTIs, including mixed/interoperability scenarios on modern IOS XE releases.

See Cisco IOS IKEv1 IPsec crypto map example (legacy) when supporting an older policy-based deployment.

Official references

See also