cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
473
Views
5
Helpful
3
Replies

hssr with static route to isp

prashantrecon
Level 1
Level 1

we have decided to configure hssrp on router with static routing.

Now the think we want to create site to site vpn on router.

Is it possible to create vpn with virual ip ?

3 Replies 3

Richard Burts
Hall of Fame
Hall of Fame

For VPN you will need to use the physical address and not the virtual address.

HTH

Rick

HTH

Rick

Is there any way to create site to site  vpn with hssrp concept ?

It is not possible to use the HSRP virtual address as the peer address for a site to site VPN. There are several reasons but the most important reason is that the IPSec negotiation between peers would fail because the router will not use the HSRP virtual address as the source address of a packet. And if the IPSec negotiation packet source address is not the peer address then the negotiation will fail.

If you are thinking of the HSRP concept in terms of providing failover capability then it may be possible to create site to site VPN using HSRP concept. On the remote router configure the IPSec with two peer addresses in the set peer statement (and configure an IPSec tunnel on each of the HSRP routers). Then the remote will negotiate one tunnel with the first router as primary and the second router as failover.

HTH

Rick

HTH

Rick
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Innovations in Cisco Full Stack Observability - A new webinar from Cisco

Ā