cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1092
Views
0
Helpful
7
Replies

ipsec(tunnelmode)+gre+eigr

adaubenton
Level 1
Level 1

is it possible to use ipsec(tunnelmode)+gre+eigrp at the sime time?

7 Replies 7

Richard Burts
Hall of Fame
Hall of Fame

It is possible. In a customer network we are doing IPSec over GRE and running EIGRP. I have configured IPSec for both tunnel mode and for transport mode. Both of them worked.

HTH

Rick

HTH

Rick

thank you, in fact my configuration work well only for 5 minutes.

my next step: CBWFQ+GTS

Bye

Arnaud

rhaeppeler
Level 1
Level 1

Hi,

we have about 50 Companies in the whole world connected via GRE over IPSec. A lot of the companies are meshed. So EIGRP can find the best way to the HQ in DE if we have Problems with the ISP. Additional we can use floating static routes to enable ISDN-Backup when Internet is down. It works fine.

Regards Rainer

Hi,

do you have any problem with splithorizon ?

On the central site, if you are connected via multi gre tunnels to other sites, using only one physical interface on the central site ?

regards Arno

The real question is not whether you are connected using a single physical interface at the central site. I have a customer who is currently using a single physical interface for about 90 GRE tunnels with no issue about split horizon. But these are traditional point to point GRE tunnels. If you connect to multiple remote locations with a multipoint GRE tunnel then there is an issue with EIGRP split horizon and you would need to turn off split horizon. If you do not disable split horizon the symptom is likely to be that all remotes can talk to the central site, the central site can talk to all remotes, but one remote will not be able to talk to other remotes.

HTH

Rick

HTH

Rick

Hello Arno,

No, we don't have a Problem with splithorizion because we have for each Company a own GRE-Tunnel (point-to-point) for the Routing-Protocol it's like a own Interface for each Branch. We don't use Multipoint GRE

Thank you for your answers Rainer and Rick, that was the point i wasn't sure about.

Arno

Review Cisco Networking for a $25 gift card