Above is the topology being setup for MPLS over FlexVPN. The main goal is to have connectivity between Customer 1 and Customer 2.

First steps are configuring FlexVPN on the Hub, R1.

  • Keyring
  • Authorization policy
  • IKEV2 Profile
  • IPSEC Profile
  • Dynamic VTI
  • VRF
  • MP-BGP

Configuration for Spoke 1:

  • Keyring
  • IKEV2 Authorization Policy
  • IKEV2 PROFILE
  • IPSEC Profile
  • Dynamic VTI
  • VRF
NOTE- this VRF is being assigned to Gig0/3 towards the Customer as well.
  • MP-BGP

Configuration for Spoke 2:

  • VRF
NOTE- this VRF is being assigned to Gig0/3 towards the Customer as well.
  • IKEV2 Authorization Policy
  • KEYRING
  • IKEV2 Profile:
  • Dynamic VTI:
  • BGP:

Leave a comment