Unanswered Question
Dec 10th, 2008
User Badges:

I have an OSPF network, backbone plus several areas. I need to encrypt certain traffic flows between the two areas via the backbone. I'd like to keep the OSPF on the outside of the VPN and essentially just enncrpt the payload of the data packets between the two areas. The main reason is I have different classifications of data or subnets. I dont particulary want to GRE tunnel OSPF, but have the IPSec sit on top if this makes sense?? Any help is appreciated. The ABRs are ASA's and 2800 ISRs.

Thanks, Wayne

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
mgajew Thu, 12/11/2008 - 01:53
User Badges:

IPSec doesn't support multicast (that OSPF is running on) so GRE is needed to build neighborship.

wrgoulden Thu, 12/11/2008 - 02:10
User Badges:


I want to avoid if possible using OSPF within IPSec as it needs to maintain Area 0 connectivity. I dont want to terminate the VPN on a backbone router and re-establish a new one either to get me to the OSPF area I need as this VPN will be point-to-point between two OSPF areas.

I've been reviewing the use of open transport VPNs where essentially I just want the payload of an IP packet encrypted and everything else to work as normal.

Thanks, Wayne


This Discussion