Re: GRE/IPSEC Tunnel and loopback interface



<Bod43@xxxxxxxxxxxxx> ha scritto nel messaggio
news:1177941940.948940.203710@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
You can use ANY ingerface on the router as a tunnel
souce/destination.

The reason that loopbacks are preferred in general is that
with some network designs it is possible for the tunnel
source/dest interface to go down and even though there
is another path the tunnel will do down too. The loopbacks are
always up.

I do not have a perfect picture of you network I don't think,
but if each router has only one outside interface
and no other path then there will be no disadvantage in
using the external interface to terminate the tunnel.
Exactly what I done!
Tunnel is absolutely a Point-to-Point one and using the loopback interface
caused some problems (see below...)

Beware recursive routing.
I ALWAYS put in static routing to the tunnel endpoints.
Ok, I experimented this :-(
I don't know exactly why but, using the loopback interface, I had some loop,
peraphs due to another indirect link between tunnel endopoints advertised by
OSPF. I was not able to filter it.

Thanks again
Mimmus


.



Relevant Pages

  • Re: Terminal Server Setup
    ... description GRE Tunnel Source Interface ... input packets with dribble condition detected ... output buffer failures, ...
    (comp.dcom.sys.cisco)
  • Re: Terminal Server Setup
    ... ~ description GRE Tunnel Source Interface ... ~ interface Serial1/0 ... ~ 0 output buffer failures, ...
    (comp.dcom.sys.cisco)
  • NAT problem over multiple links
    ... Dialer 4 is the primary link and Dialer 3 is the secondary ... interface Tunnel1 ... description Tunnel FForestTelstra to AlexandriaPT ... access-list 1 permit 202.154.79.0 0.0.0.7 ...
    (comp.dcom.sys.cisco)
  • Re: OpenVPN server (win32) wrong Netmask
    ... Laptop and server1 are both windows 2000 machines. ... An IP tunnel has two sets of addresses: ... When doing basic routing, the route ... local tun interface directly ...
    (comp.os.linux.networking)
  • RE: [fw-wiz] Pix LAN-To-LAN Problem
    ... and attempt to bring the tunnel up. ... access-list bound to the inside interface (or whichever interface the ... local VPN traffic arrives at the firewall. ... > I have a border router above my firewall and no ...
    (Firewall-Wizards)