Re: VPN between Concentrator & Router
- From: Darren Green <darrenfgreen@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Mon, 08 May 2006 21:56:58 +0100
rdymek wrote:
One problem with redistribution is that your administrative distance isRyan,
no longer the same (although is configurable), and you are still
dependant on a static route somewhere in the scheme.
I actually recommend a slightly more complex solution using GRE
(although not too complex) but seems to work a lot better in my
opinion. Since IPSec tunnels don't support any routing protocols
you'll either have to use purely static routes, or redistribute static
routes from the concentrator on the inside. In either case, you're
still dependant on static routing being redistributed. Not to mention
the other end (the branch office) still doesn't have dynamic routing
with this option.
I find that a GRE tunnel does the trick. You'd have to make the VPN
router a GRE tunnel end point, and the 2800 router on the inside of the
concentrator a GRE end point. There is lots of documentation on
Cisco's site about using GRE. Some solutions you'll find piggyback on
the IPSec configuration, using the same end points as the IPSec end
points for GRE. This is fine if you are using two routers for IPSec,
but a concentrator does not support itself being a GRE end piont. So
when looking through various documentation, be aware that this is not
really GRE over IPSec, its completely independent from your IPSec
tunnel; however, does pass through the IPSec tunnel.
With GRE you can run OSPF, EIGRP or just about any other routing
protocol you may be using.
By doing this you can effectively send your routing protocol through
the IPSec tunnel -- this opens many doors that you just can't do with
static routing, even being redistributed. You can perform automatic
load balancing or any other features of your dynamic protocol you may
want to do - it could at this point be treated as if it were a regular
point-to-point office.
Ryan
Thanks for the response and to Merv as well in the earlier post.
I will re-work the config along these lines.
Regards
Darren
.
- References:
- VPN between Concentrator & Router
- From: Darren Green
- Re: VPN between Concentrator & Router
- From: Merv
- Re: VPN between Concentrator & Router
- From: rdymek
- VPN between Concentrator & Router
- Prev by Date: WIC-1T won't work on 2620 router
- Next by Date: Re: Cisco PIX 501: Can't ping global IP-Adress from NATed IP
- Previous by thread: Re: VPN between Concentrator & Router
- Next by thread: Unified Messaging over VPN
- Index(es):
Relevant Pages
|