Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
New Member

OSPF via IPSEC (7206 IOS 12.2)

IPSEC does not support IP multicast packet

I need to encrypt OSPF over ATM PVC (ip ospf network point-to-point);

to do so, I could use GRE + IPSEC to encrypt OSPF like other date flows;

due to different customer-related reasons, we would like to avoid GRE, but rather

force OSPF to send only unicast packets over ATM PVC, if possible, and so, make

possible OSPF encryption with pure IPSEC (without GRE) ;

question : is it possible to force OSPF doing so ?

New Member

Re: OSPF via IPSEC (7206 IOS 12.2)

IPSec also does not support routing protocols, such as Enhanced Interior Gateway Routing Protocol (EIGRP) and Open Shortest Path First (OSPF), or non-IP traffic, such as Internetwork Packet Exchange (IPX) and AppleTalk.Hence the use of GRE. If you are not comfortable with GRE the only thing taht comes to my mind is CET which can replace GRE.


Re: OSPF via IPSEC (7206 IOS 12.2)

If you want to run OSPF over IPsec, you will need to do so over a GRE tunnel. The same goes for EIGRP, RIP and all other interior gateway protocols. However, you can run BGP through an IPsec tunnel with using a GRE tunnel. See the "Redundant Routes in IPsec VPNs" white paper on my web site for a discussion of the alternatives and examples of both OSPF over GRE over IPsec and BGP over IPsec with no GRE.

Good luck and have fun!

Vincent C Jones

CreatePlease to create content