07-23-2012 10:46 AM - edited 03-04-2019 05:03 PM
I have several IPsec vpn tunnels to the main site. The remote locations are using 871 routers and the main site is using an ASA 5510. I am using the tunnels for both voice and data. I would like to implement Rip or some type of dynamic routing between them. but according to what I have found using IPsec it is not possible.
Is this true and if so what are my options.
07-23-2012 12:31 PM
If you are looking for spoke-spoke connectivity DMVPN would be the best option where routing protocols can be employed for dynamic routing. However, DMVPN used when there are a quite a lot of sites requiring inter-site connectivity.
If you want dynamic routing to be used across sites your options are GRE tunnels and DMVPN. Else, if you have few sites that have to be connected, static routes can do the job for you.
-Karthic
07-23-2012 12:42 PM
Right now they have static routes, but a couple of days ago one site went down and it was a mission to change all the routes temporary and then put them back when the site came back. so im looking for a permanent solution.
07-23-2012 01:00 PM
Hello Joli,
to support GRE over IPSec or DMVPN ( that is MGRE over IPSec) you would need an IOS router at central site instead of the ASA.
As far as I know ASA doesn't support GRE over IPSec.
With GRE or mGRE you can deploy a routing protocol.
see
http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/DMVPDG.html
http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/P2P_GRE_IPSec/P2P_GRE.html
DMVPN is to be preferred if the number of sites is high as it allows to make hub configuration indipendent of the number of spokes.
Hope to help
Giuseppe
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide