Re: GRE high availability with HSRP routers
- From: "ciscodagama@xxxxxxxxx" <ciscodagama@xxxxxxxxx>
- Date: 28 Feb 2006 08:57:13 -0800
profile0104 wrote:
Though very useful, the presentation does not completely cover my case.
To sum it up:
1) Main site has 2 routers in HSRP, with one external VIP and one
internal VIP.
When you write VIP, do you mean virtual IP? What you mean by
external/internal VIPs?
The two routers running HSRP are one end of the IPSec connection.
What's at the other end?
2) I want to set up GRE over IPSec.
3) Documentation I found suggests to use the external VIP as the tunnel
source
The tunnel source will be the IP address of the physical interface the
tunnel is bound to at the local end, and the tunnel destination will be
the IP address of the physical interface that is the destination of the
tunnel. Note that these tunnel source and destination IP addresses are
not the HSRP virtual IP addresses.
4) But what's the tunnel's interface (the one I will use with dynamic
routing)? Can (must) I configure two different tunnel interfaces?
You will have to configure one tunnel interface on each of the HSRP
routers, and two tunnel interfaces (pointing at each of the HSRP
routers) on the far end router. Then you will run transport mode IPSec
on the GRE tunnels and also run a routing protocol over the tunnels.
The routing protocol will allow you load-balance over the two GRE
tunnels. When one HSRP router goes down, the routing protocol will
converge and stop using the GRE tunnel pointing at the HSRP router that
is now down. Note carefully the config of the routing protocol in the
example with passive interface commands that makes sure using the
routing protocol that the tunnel of the HSRP router that goes down is
no longer used by the far-end router.
Cisco da Gama
http://ciscostudy.blogspot.com
.
- Follow-Ups:
- Re: GRE high availability with HSRP routers
- From: profile0104
- Re: GRE high availability with HSRP routers
- References:
- GRE high availability with HSRP routers
- From: profile0104
- Re: GRE high availability with HSRP routers
- From: ciscodagama@xxxxxxxxx
- Re: GRE high availability with HSRP routers
- From: profile0104
- GRE high availability with HSRP routers
- Prev by Date: Cisco 4500m
- Next by Date: Re: 1200 Access Points as Bridged Network
- Previous by thread: Re: GRE high availability with HSRP routers
- Next by thread: Re: GRE high availability with HSRP routers
- Index(es):
Relevant Pages
|