vpn 3000 concentrator and redistributing static routes in to OSPF
Have a problem with redistribution . We have 2 data centers with VPN 3000-s.
OSPF routing in our core. VPN concentrator #1 has static route pointing to remote site with metric 1. VPN concentrator #2 has static to same remote site with metric 10. Both redistributing static in to OSPF core.
Routers in the core see remote site network with ospf e2 (110/20) for both.
How can I change config on VPN 3000 concentrator to enable redistribution so routers in the core can see: ospf e1 (110 /1) and ospf e1 (110/10) . So I can force trffic trough VPN 3000 concentrator #1
My goal is to have different metric in te core ...Any suggestions?
Re: vpn 3000 concentrator and redistributing static routes in to
I don't think changing the metric on the static route is going to change the metric when it gets re-advertised into OSPF. If conc #2 is a backup for #1, so you always want #2 to advertise a higher OSPF cost, then go under the Private interface of this concentrator, click on the OSPF tab and change the OSPF Metric to 10. That should change the OSPF routes you see on your inside network.
Another way to do this is to enable Reverse-Route Injection (RRI), so that #1 will automatically advertise the remote route when the tunnel is up. If the tunnel goes down, it stops advertising the route, and if the tunnel comes up on #2 then it'll start advertising it. You do this under the L2L tunnel config under the Routing drop-down box.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :