Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Dynamic IPSec??

Friends,

I am working on wan project that includes 24 sites. All sites are connect with each other like partial mesh and run ospf routing protocol. We need that user data move from one site to an other site in encrypted form. For example, if user of site A send data to the user of Site F then it pass through router of site B, C, D and E. Now one way of using ipsec, i make site to site vpn between A and B then B and C then C and D and so on. So while packet move from site A to site F will encrypted and decrypted on all hops.

My question, is there any other dynamic way in which if packet source is A and dest is F then an ipsec tunnel created from A to direct F.

I know a method called multiple gre (MGRE) but i dont want to involve jre in it.

I will be thankful, if someone respond on it.

Best Regards

3 REPLIES
Gold

Re: Dynamic IPSec??

Dynamic Multipoint VPN is probably what you need. aka DMVPN. You have your work cut out for you.

http://www.cisco.com.ru/en/US/docs/ios/12_2t/12_2t13/feature/guide/ftgreips.html

New Member

Re: Dynamic IPSec??

Dear,

Thanks for your reply. Tell me can we cut out GRE from this technique?? Since i mentioned in post that i don't want to involve GRE.

Best Regards

New Member

Re: Dynamic IPSec??

From everything that I have read, I would have to say, "No." I think the answer lies in the fact that IPSec doesn't carry routing protocols.

180
Views
0
Helpful
3
Replies