Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

hssr with static route to isp

we have decided to configure hssrp on router with static routing.

Now the think we want to create site to site vpn on router.

Is it possible to create vpn with virual ip ?

Everyone's tags (4)
3 REPLIES
Hall of Fame Super Gold

hssr with static route to isp

For VPN you will need to use the physical address and not the virtual address.

HTH

Rick

New Member

hssr with static route to isp

Is there any way to create site to site  vpn with hssrp concept ?

Hall of Fame Super Gold

hssr with static route to isp

It is not possible to use the HSRP virtual address as the peer address for a site to site VPN. There are several reasons but the most important reason is that the IPSec negotiation between peers would fail because the router will not use the HSRP virtual address as the source address of a packet. And if the IPSec negotiation packet source address is not the peer address then the negotiation will fail.

If you are thinking of the HSRP concept in terms of providing failover capability then it may be possible to create site to site VPN using HSRP concept. On the remote router configure the IPSec with two peer addresses in the set peer statement (and configure an IPSec tunnel on each of the HSRP routers). Then the remote will negotiate one tunnel with the first router as primary and the second router as failover.

HTH

Rick

274
Views
5
Helpful
3
Replies
CreatePlease to create content