Cisco IOS IPsec VTI setup and troubleshooting
More actions
Configure the IPsec Virtual Tunnel Interface (VTI) data plane on Cisco IOS XE and use current verification commands when troubleshooting tunnel establishment and traffic flow.
VTI structure
An IPsec VTI uses a routed tunnel interface associated with an IPsec profile. Current IOS XE documentation supports this model for IPv4 and IPv6.
Define the required transform set according to the approved cryptographic policy for the deployment.
crypto ipsec transform-set VTI-TSET esp-aes 256 esp-sha256-hmac mode tunnel
Create an IPsec profile and associate the transform set:
crypto ipsec profile VTI-PROFILE set transform-set VTI-TSET
Configure the tunnel interface:
interface Tunnel0 ip address 192.0.2.1 255.255.255.252 tunnel source GigabitEthernet0/0 tunnel destination 203.0.113.2 tunnel mode ipsec ipv4 tunnel protection ipsec profile VTI-PROFILE
The peer must be configured with compatible IKE/IPsec parameters and appropriate routing.
Troubleshooting workflow
Start with the routed interface and crypto-session state before enabling debugging.
show interfaces Tunnel0 show ip route
Review the overall crypto session and IPsec security associations:
show crypto session show crypto ipsec sa
For IKEv2 deployments, also review the IKEv2 security association:
show crypto ikev2 sa
For legacy IKEv1 deployments, use the applicable ISAKMP/IKEv1 commands for that platform and release.
What to check
When a VTI does not pass traffic, verify:
- The tunnel source and destination are reachable outside the VPN.
- The IKE peer identity and authentication match at both ends.
- IKE and IPsec algorithms have a compatible proposal.
- The tunnel interface has the expected line protocol state.
- Routing sends the protected networks towards the tunnel interface.
- IPsec packet counters increment for both encapsulation and decapsulation.
- NAT or policy-based controls are not unexpectedly changing the protected traffic.
- MTU/MSS behaviour is appropriate for the additional IPsec overhead.
show crypto session and show crypto ipsec sa often identify whether the problem is IKE establishment, IPsec SA creation, routing or one-way traffic without the operational impact of verbose debugging.Migration from crypto maps
Cisco documents migration options from policy-based crypto maps to VTIs, including mixed/interoperability scenarios on modern IOS XE releases.
See Cisco IOS IKEv1 IPsec crypto map example (legacy) when supporting an older policy-based deployment.