cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
580
Views
0
Helpful
1
Replies

GRE Tunnels and Firewall

dave.ellis
Level 1
Level 1

I have about 12 remote sites all connected to a central Cisco 2811 router using GRE tunnels across ADSL. The 2811 is separated from the Central LAN by a Nokia firewall.At the moment all the remote sites can route to each other via the central 2811 router but I want all this traffic to go through the firewall so I can do some filtering (don't really want to use ACLs as I want to centralise the filtering on the firewall). The only 2 options I can think of are to either create a GRE tunnel directly from the remote router and the Nokia firewall (don't like the idea of this though). Alternatively create a route-map to force all traffic incoming from each remote site up to the firewall. I tried the route-map some time ago and had some problems though. Anyone have any other suggestions ? Thanks

1 Reply 1

Richard Burts
Hall of Fame
Hall of Fame

Dave

It seems to me that the best option is Policy Based Routing to take traffic that comes in on a GRE tunnel and send it out the interface to the firewall.

I am not sure what problem you had before when you tried it. But I believe the PBR would work for you to accomplish what you need.

HTH

Rick

HTH

Rick