cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
486
Views
5
Helpful
3
Replies

hssr with static route to isp

prashantrecon
Level 1
Level 1

we have decided to configure hssrp on router with static routing.

Now the think we want to create site to site vpn on router.

Is it possible to create vpn with virual ip ?

3 Replies 3

Richard Burts
Hall of Fame
Hall of Fame

For VPN you will need to use the physical address and not the virtual address.

HTH

Rick

HTH

Rick

Is there any way to create site to site  vpn with hssrp concept ?

It is not possible to use the HSRP virtual address as the peer address for a site to site VPN. There are several reasons but the most important reason is that the IPSec negotiation between peers would fail because the router will not use the HSRP virtual address as the source address of a packet. And if the IPSec negotiation packet source address is not the peer address then the negotiation will fail.

If you are thinking of the HSRP concept in terms of providing failover capability then it may be possible to create site to site VPN using HSRP concept. On the remote router configure the IPSec with two peer addresses in the set peer statement (and configure an IPSec tunnel on each of the HSRP routers). Then the remote will negotiate one tunnel with the first router as primary and the second router as failover.

HTH

Rick

HTH

Rick
Review Cisco Networking products for a $25 gift card