02-15-2012 01:57 AM - edited 03-04-2019 03:16 PM
Hi All,
I have below switch and I was interested in configuring GRE on one of the interface. So I tried to create tunnel interface, the tab completes the command. Is GRE supported on this switch and IOS?
Switch#show version
Cisco IOS Software, C3560 Software (C3560-IPBASE-M), Version 12.2(35)SE5, RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2007 by Cisco Systems, Inc.
......
cisco WS-C3560-48TS (PowerPC405) processor (revision G0) with 122880K/8184K bytes of memory.
Switch(config)#interface tunnel 0
^
% Invalid input detected at '^' marker.
Switch(config)#
IP routing is also enabled. Your quick help is higly appreciated.
Regards,
Ravi
Solved! Go to Solution.
02-15-2012 02:18 AM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
I have below switch and I was interested in configuring GRE on one of the interface. So I tried to create tunnel interface, the tab completes the command. Is GRE supported on this switch and IOS?
No, it's not supported except as transit traffic.
02-15-2012 03:25 AM
Hi Ravi,
There is no option to configure vpn tunnel on 3560's.
You can use this switch as a transit I mean end users can connect to this switch and can forward the encrypted traffic through this switch.
You need toh ave a additional ASA or any ISR router to configure a site to site vpn or client vpn.
You may heard about VPN Routing/Forwarding Lite (VRF Lite) supported in the Cisco Catalyst 3560 Series helps enable unique VPNs without additional equipment at the customer site.
Please rate all the helpfull posts.
Regards,
Naidu.
02-15-2012 07:12 AM
As correctly indicated above.
you should NOT terminate tunnels on the switch. The reson is that you will have poor performances, limited features, and risk to introduce instability in the network.
Moreover, per Cisco licensing terms, upgrading a switch to ip service images, require that you buy a license.
02-15-2012 02:18 AM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
I have below switch and I was interested in configuring GRE on one of the interface. So I tried to create tunnel interface, the tab completes the command. Is GRE supported on this switch and IOS?
No, it's not supported except as transit traffic.
02-15-2012 03:25 AM
Hi Ravi,
There is no option to configure vpn tunnel on 3560's.
You can use this switch as a transit I mean end users can connect to this switch and can forward the encrypted traffic through this switch.
You need toh ave a additional ASA or any ISR router to configure a site to site vpn or client vpn.
You may heard about VPN Routing/Forwarding Lite (VRF Lite) supported in the Cisco Catalyst 3560 Series helps enable unique VPNs without additional equipment at the customer site.
Please rate all the helpfull posts.
Regards,
Naidu.
02-15-2012 06:33 AM
Please upgrade the IOS image to ip-service version, that should fix up the problem.
c3560-ipservicesk9-tar.122-55.SE4.tar
Thanks
Rizwan Rafeek
02-15-2012 06:52 AM
Hi Rizwan,
Thanks, let me download and give it a go.
Regards,
Ravindra
02-15-2012 07:12 AM
As correctly indicated above.
you should NOT terminate tunnels on the switch. The reson is that you will have poor performances, limited features, and risk to introduce instability in the network.
Moreover, per Cisco licensing terms, upgrading a switch to ip service images, require that you buy a license.
02-15-2012 07:25 AM
Where do you recommand that tunnel should be terminated to that a customer who has only 3560es and ASA Firewall carring GRE over IPSec?
02-15-2012 07:27 AM
Hi Paolo,
I just have C3560 in my lab currently up and working :-(. So was desperate, I think I need to wait untill tomorrow.
Reg,
Ravindra
02-15-2012 07:29 AM
Thanks All.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: