See attached - might make question more clear
we have a layer 2 connection between sites using a local provider for the link. On the remote side is a 3750-X and on the Main Campus side is a 2960. The link is connected via a VLAN. The VLAN interface exists on the Main Campus 5548, core switch
From What I understand, Trustsec cannot be configured on a logical interface but, if we were to configure the logical interfaces as a physical interfaces could we encrypt traffic between the 5548 and the 3750-X?
Even though it would also have to traverse through the 2960 as well?
And traverse the Layer 2 WAN link?
Any other suggestions for accomplishing this?
Thank you, Pat
Trustsec is supported on SVIs, but I think in order for it to work correctly, you would need to configure it on every device including 5500, 2900, 3750.
See table-1 in this link:
No, it is not supported on the 2960 series. Also, if you want to encrypt traffic between sites, a better solution is to use IPsec tunnel, but you need a firewall or a router in each location.
It doesn't have to be anything expensive if you don't need a lot of bandwidth.
I use these and they work really well.
have a look:
Are you sure, you are pushing 800Mb traffic. I don't think the 2960 can handle that much traffic. I would look at your data and figure out how much traffic you are really pushing. What I recommended was 10/100. You can go to a Gig device for a little more money. What is your circuit speed to the provider?
The circuit speed is an 800 Mbps Fairpoint link between buildings that are roughly 2 miles apart. We don't usually saturate the link but, 800 Mbps is what we pay for.
Understand. Here is another one I use a lot. It costs a little more money, but it comes with 2 1Gig interfaces and 6 10/100. For IPsec, you only need 2 interfaces (one inside and one outside) which you can use the Gig interfaces for..
Thanks Reza -
Actually just realized that trustsec might not be what I am looking for. I'm looking to encrypt traffic between sites. Is this possible with the present equipment setup?