Hi all,
when setting up a route-based VPN tunnel, the IP configuration for the xfrm interface is necessary to enable it. On other firewalls a IP configuration is not required, unless you want to do monitoring or OSPF, etc. I assume I do not need the other peer to have an IP in the same subnet on their VTI, unless we want to monitor? Otherwise migrating to XG would require us to contact all other peers and reconfigure their tunnels. I can create a static route based on the interface, so it shouldn't be a problem to route the traffic into the tunnel regardless.
Regards
This thread was automatically locked due to age.