the “tunnel 1” refers to an actual tunnel that’s configured not in vti mode. it appears that it’s not able to be disabled in that area of the config when using vti, but I think that it should be allowed.
in /opt/vyatta/sbin/vpn-config.pl line 479 implies that it should allow for disabling vti using “set ipsec site-to-site peer vti disable”
vyos@vyos# set vpn ipsec site-to-site peer 52.18.245.190 vti
Possible completions:
bind VTI tunnel interface associated with this configuration [REQUIRED]
esp-group ESP group name [REQUIRED]
[edit]
vyos@vyos#