cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
482
Views
0
Helpful
3
Replies

Dynamic IPSec??

rameezsardar
Level 1
Level 1

Friends,

I am working on wan project that includes 24 sites. All sites are connect with each other like partial mesh and run ospf routing protocol. We need that user data move from one site to an other site in encrypted form. For example, if user of site A send data to the user of Site F then it pass through router of site B, C, D and E. Now one way of using ipsec, i make site to site vpn between A and B then B and C then C and D and so on. So while packet move from site A to site F will encrypted and decrypted on all hops.

My question, is there any other dynamic way in which if packet source is A and dest is F then an ipsec tunnel created from A to direct F.

I know a method called multiple gre (MGRE) but i dont want to involve jre in it.

I will be thankful, if someone respond on it.

Best Regards

3 Replies 3

srue
Level 7
Level 7

Dynamic Multipoint VPN is probably what you need. aka DMVPN. You have your work cut out for you.

http://www.cisco.com.ru/en/US/docs/ios/12_2t/12_2t13/feature/guide/ftgreips.html

Dear,

Thanks for your reply. Tell me can we cut out GRE from this technique?? Since i mentioned in post that i don't want to involve GRE.

Best Regards

From everything that I have read, I would have to say, "No." I think the answer lies in the fact that IPSec doesn't carry routing protocols.