24-15
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter24 Managing Site-to-Site VPNs: The Basics
Understanding IPsec Technologies and Policies
The following illustration shows the topology of a one-box solution.
Figure 24-4 VRF-Aware IPsec One-Box Solution
Related Topics
Understanding VRF-Aware IPsec, page 24-14
Configuring VRF Aware IPsec Settings, page24-46
Defining the Endpoints and Protected Networks, page 24-33
VRF-Aware IPsec Two-Box Solution
In the two-box solution, the PE device does just the MPLS mapping, while a separate IPsec Aggregator
device does the IPsec encryption and decryption from the CEs.
Note Security Manager fully manages the IPsec Aggregator, including routing to the PE device. The PE device
is fully managed by Cisco IP Solution Center. This includes routing between the PE device and the
MPLS cloud, and routing from the PE to the IPsec Aggregator. For more information, see the Cisco IP
Solution Center MPLS VPN User Guide.
The following illustration shows the topology of a two-box solution.