VTI interface down because interface number created is greater than ipsec32768
In some conditions, when creating a VTI interface for routed IP, the interface number allocated is very high.
This seems to be happening with firewalls that already have a large number of traditional ipsec p1/p2 tunnels. The first VTI p2 I made started with ipsec52000 and the interface is permanently offline / down. Any additional VTI interfaces I create get an even higher interface number such as ipsec53000.
Obviously this breaks the VTI and you cannot get routed IP to work.