Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
You may experience some slow load times, errors, and slight inconsistencies. We ask for your patience as we finalize the launch. Thank you.

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN Ipsec (160 Remode Nodes Connecting to 2 Central Nodes)

Hello,

I want to connect 160 Cisco Routers 2621 Remode Nodes to my Central nodes that they are 2 Cisco Routers 7206VXR.All routers have 2 Wan serial for redudancy and my 7206VXR are running Hsrp.also I am running a dynamic routing protocol Eigrp.I am wondering which is the best configuration to implement this scenario.I have read about Ipsec Vpn High Availability that i can terminate the Ipsec tunnels to the Hsrp address of 7206, the configuration that i found have as outside interface ethernet interface .Can I do the same if I have outside interface serial interfaces?

Thanks in advance

  • Other Security Subjects
2 REPLIES
New Member

Re: VPN Ipsec (160 Remode Nodes Connecting to 2 Central Nodes)

I believe that with HSRP, the IP address of all devices in the group and the standby IP have to be in the same subnet. This is not likely the scenario with multiple serial connections.

I did a little digging just now, and with my experience with HSRP, I believe this to be true.

New Member

Re: VPN Ipsec (160 Remode Nodes Connecting to 2 Central Nodes)

I would probably just configure both peers on each of the remote routers. You can do it simply (two set peer commands) or with two crypto map instances. If you do seperate instances you can load balance the central site routers more effectively.

hope this helps

tim

101
Views
0
Helpful
2
Replies