cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
523
Views
5
Helpful
4
Replies

Routing through IPSEC

Mirko442
Level 1
Level 1

Hello everyone,

 

Here's my topology:

Mirko442_0-1674572353837.png

I have issue with traffic going to wrong IPSec when trying to use backup link. So the blue squares are communicating with eachother through IPSEC on the pink link that is going through ISP (when MPLS is down, they communicate through internet links). They also have IPSEC+GRE tunnel between JA1 and JA2 router for PC4 communication. So I've configured backup link for communication between blue squares (Split, Makarska, Imotski) and yellow circle where PC4 is in case JA1 and JA2 router go down. HSRP is configured between CE-ST, JA1 and JA2, my backup route used to work fine until I configured IPSec+GRE tunnel between JA1 -> Split, Makarska and Imotski, JA2 -> Split, Makarska and Imotski. Now when I try to use backup link (ping from PC in Makarska or Imotski) the traffic towards PC4 its going through IPSEC+GRE to JA1 router (even tho its interface towards ISP is down)  and not to CE-ST where backup link is.

 

Traceroute from CE-MA (Makarska router) towards the PC4 (10.30.7.1) is going through the backup link:

Mirko442_0-1674573176762.png

 

 

4 Replies 4

Mirko442
Level 1
Level 1

My configs of involved routers:

Mirko442
Level 1
Level 1

Updated my topology and added config of involved routers(on JA2 i didn't config IPSEC+GRE yet, till I solve this issue). Interface towards the ISP is where the IPSEC tunnel between Split, Makarska and Imotski is configured, on JA1 router I've configured IPSEC+GRE towards Split, Makarska and Imotski also on the interface towards the internet.

Mirko442_2-1674589601152.png

 

Why you config GRE+IPSec between two edge routers ?? how this help you ?

Mirko442
Level 1
Level 1

GRE+IPSEC is configured between: JA1 and CE-ST, JA1 and CE-MA, JA1 and CE-IM so PC1,PC2 and 3 can communicate with PC4 through tunnel

Review Cisco Networking for a $25 gift card