# FlexVPN IKEv2 Routing

**URL:** https://forum.networklessons.com/t/flexvpn-ikev2-routing/13256
**Category:** Lessons Discussion
**Created:** [January 6, 2021, 1:42pm UTC](https://forum.networklessons.com/t/flexvpn-ikev2-routing/13256 "2021-01-06T13:42:30Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [January 6, 2021, 1:42pm UTC](https://forum.networklessons.com/t/flexvpn-ikev2-routing/13256/1 "2021-01-06T13:42:30Z")

</div>

This topic is to discuss the following lesson:

> **[FlexVPN IKEv2 Routing](https://networklessons.com/vpn/flexvpn-ikev2-routing)**
>
> This lesson explains how to configure FlexVPN IKEv2 routing which advertises routes within the IKEv2 Security Association (SA).

---

<div class="post-metadata">

### Author: ![raviluchmun](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/r/ea5d25/32.png) [@raviluchmun](https://forum.networklessons.com/u/raviluchmun)
#### Post date: [April 7, 2025, 5:32pm UTC](https://forum.networklessons.com/t/flexvpn-ikev2-routing/13256/3 "2025-04-07T17:32:30Z")

</div>

I tested this in a lab and pings only work if the `tunnel mode` is left in the default tunnel mode gre.  
I changed my tunnel mode to `tunnel mode ipsec ipv4` and whilst the tunnel establishes and IKEv2 shares the route, traffic doesn’t flow.  
Is this an expected behaviour ?  
Thank you

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [April 10, 2025, 4:41am UTC](https://forum.networklessons.com/t/flexvpn-ikev2-routing/13256/4 "2025-04-10T04:41:55Z")

</div>

Hello Ravi

FlexVPN tunnel interfaces typically use GRE over IPsec. This means the router first encapsulates packets in a GRE header, then encrypts them with IPsec.

When you specify `tunnel mode ipsec ipv4` without GRE, the tunnel becomes a pure IPsec interface or a VTI. FlexVPN supports this configuration mode, and can indeed function using IKEv2 routing as well, but you need to add some additional changes.

You must use a transform set ACL or Crypto Map ACL that permits traffic. Even though you’re using a profile (and not classic crypto maps), IPsec still requires a match for interesting traffic. Right now, your `crypto ipsec profile default` has no explicit transform-set ACL. So consider configuring an explicit transform set and ACL. For more info, take a look at [this lesson](https://networklessons.com/cisco/ccie-enterprise-infrastructureipsec-vti-virtual-tunnel-interface).

Once that’s done and the tunnel is up, try pinging the tunnel interfaces. If that fails, traffic is likely not being encrypted properly. Some additional troubleshooting commands you can use include `show crypto ikev2 sa` and `show crypto ipsec sa`.

Let us know how you get along!!

I hope this has been helpful!

Laz
