05-10-2010 01:39 PM - edited 03-06-2019 11:01 AM
Hey all,
I have been very unsuccessful in finding a solution to this issue and am begining to believe that it is not possible...well, at least as we would like to do it.
Our situation: We have a 6509-E (SUP-720, VSPA) that is the hub to several 2960's connected (dot1Q) to remote sites (2-13 miles away) via our own fiber (no ISP).
Our objective: We are wishing to encrypt the traffic over that fiber to help us comply with DoD requirements. We have some 3825's that we would like to place at each of the sites in front of the 2960's.
Our problem: We do not want to have to route the traffic. We have several VLANs distributed at each of those sites. These VLANs are required to separate the data from eachother, again to help comply with DoD requirements.
Is this doable? If so, where can I get some additional info?
Thanks!
Cliff Goniea
05-10-2010 01:46 PM
Hello Cliff,
you should use L2TPv3 and you should protect L2TPv3 with IPSec between a pair of C3825.
be aware that you can face performance issues. so even if technically it can be done it is not recommended.
Routing using GRE tunnels or DMVPN would be a far better solution, once you deploy a C3825 on each site you can do routing and if you can do it you should do.
You could in this way use IPSec encyption to protect routed traffic and you wouldn't waste WAN bandwidth propagating broadcast frames.
Hope to help
Giuseppe
05-10-2010 02:12 PM
Hi Cliff,
You can use the 3800 to do type-2 encryption (IPSEc) from your remote location. If you need to have separation then you can use VRF to that for you.
HTH
Reza
05-10-2010 03:16 PM
I can't say for DoD, but here in Australia, we follow guidelines set by DSD. DSD doesn't like dot1Q trunking. We need to use GRE over IPSec or IPSec.
Just double check with the manual because western nation, including Australia, UK, Germany, France, etc. share a common guidelines called Common Criterea (CC).
02-11-2011 11:52 AM
For anyone also looking for this solution...Cisco's official stance on this subject is that it is not supported. If I figure a way to make it work, I hope to remember to come here and post the solution.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide