Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Replacing a 2611 with PIX 515E + PIX 7.2

I have three IOS routers in different sites all interconnected via OSPF over GRE over IPSec. It's working perfectly. One of the routers at one of the sites is getting overloaded due to the IPSec, so I want to replace it with a PIX running 7.2 code.

The PIX doesn't support GRE so I have to re-think how this is all setup and I'm looking for suggestions. I'm not sure if I should get rid of GRE across the board and just do OSPF over IPSec (I'm not sure if IOS can do straight OSPF over IPSec without a tunnel of some sort, but it appears PIX 7.2 can) or what my options are here.

Any thoughts welcome.


Re: Replacing a 2611 with PIX 515E + PIX 7.2

you can monitor in Performance Monitor and describes supported software versions on those devices. The software versions that you can use on a device are limited in all cases by what can actually run on the device and are further limited in some cases by restrictions that Performance Monitor imposes. The router 2611 running 12.3(7)T can be replaced with 515E, 520, 525, 535 running software version 6.3(4), 7.0(x), or 7.1(x)

New Member

Re: Replacing a 2611 with PIX 515E + PIX 7.2

If the routers are working perfectly, I would stick with it. Upgrade router model, if you are not using XM model go with add AIM-VPN/EPII-PLUS if needed for your IPSEC issue.