Specifying an inside VPN instance for the IKEv2 profile

About specifying an inside VPN instance for an IKEv2 profile

The inside VPN instance determines where the device should forward received IPsec packets after it de-encapsulates the packets. If you specify an inside VPN instance, the device looks for a route in the specified VPN instance to forward the packets. If you do not specify an inside VPN instance, the internal and external networks are in the same VPN instance. The device looks for a route in this VPN instance to forward the packets.

Procedure

  1. Enter system view.

    system-view

  2. Enter IKEv2 profile view.

    ikev2 profile profile-name

  3. Specify an inside VPN instance.

    inside-vrf vrf-name

    By default, no inside VPN instance is specified for an IKEv2 profile. The internal and external networks are in the same VPN instance. The device forwards protected data to this VPN instance.