Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

HSRP IPSec running at two sites possible?

Hello. The documentation that I've read on HA IPSec utilizing HSRP shows a headend site utilizing two routers running HSRP and the branch office running one router.

I was wondering if you can run IPSec in HA mode utilzing HSRP at both the headend and remote locations? So instead of the headend site having a set peer address of the physical interface of the branch router I would point it to the HSRP IP at the branch office.

I've tried this and it doesn't seem to work. Even though the branch office is setup with IPSec in HA mode the HSRP primary router still uses the physical interface IP when it initiates the tunnel.

Thanks

1 REPLY
Anonymous
N/A

Re: HSRP IPSec running at two sites possible?

HSRP is designed to provide high network availability by routing IP traffic from hosts on Ethernet networks without relying on the availability of any single router. By providing network redundancy for IP networks, user traffic immediately and transparently recovers from first hop failures in network edge devices or access circuits.

It requires a broadcast network.

http://www.cisco.com/en/US/products/ps6550/products_white_paper09186a0080116d4c.shtml

101
Views
0
Helpful
1
Replies