cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
651
Views
0
Helpful
2
Replies

DMVPN - Split GRE and Encryption

jsluzewski
Level 1
Level 1

I am planning for DMVPN deployment where the hub router is going to be directly connected to the Internet while spokes will reside behind firewalls (PIX 501s). I would like spokes to do just the multipoint GRE and offload encryption to firewalls. The hub router will terminate both mGRE and IPSec. Will it work?

I don't care much for spoke to spoke connectivity.

2 Replies 2

gbudd12345
Level 1
Level 1

I can't see any reason why this wouldn't work. I havn't done specific DMVPN though PIXs, but I have done just site-specific GRE though PIXs and didn't have a problem with it.

In your scenario was PIX encrypting the GRE traffic, or it was just passing traffic that was alread encrypted by the internal router?