I have an OSPF network, backbone plus several areas. I need to encrypt certain traffic flows between the two areas via the backbone. I'd like to keep the OSPF on the outside of the VPN and essentially just enncrpt the payload of the data packets between the two areas. The main reason is I have different classifications of data or subnets. I dont particulary want to GRE tunnel OSPF, but have the IPSec sit on top if this makes sense?? Any help is appreciated. The ABRs are ASA's and 2800 ISRs.