cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
931
Views
0
Helpful
4
Replies

tunnel interfaces global or private ip

pcfreak49
Level 1
Level 1

I have a question about a tunnel interface is that the sources and destination IP address or the global private IP address?

4 Replies 4

Richard Burts
Hall of Fame
Hall of Fame

Perhaps  you can clarify what you are trying to find out. The title of the question seems to imply that the question is about whether the tunnel addresses are global or private. But when I read the text of the question that does not seem to be what you are asking.

There is one thing to remember about tunnel addresses, and perhaps this will help to answer your question, there must be functioning IP connectivity between the source and destination addresses of the tunnel. When a router tries to bring up a tunnel interface the packets with its source address of the tunnel must be able to be delivered to the destination address of the other router. Sometimes that connectivity requires public addresses and sometimes it can be done with private addresses.

HTH

Rick

HTH

Rick

Okay I want site to site ipsec tunnels with multiple router as you can on the interfaces, but when a crypto map set so I used a tunnel interface is now my question about the sources and destination IP addresses are public or private IP addresses that for that purpose?

As I tried to explain in my previous post, sometimes it works ok to use private addresses as the source and destination address for the tunnel and sometimes it requires public addresses. You can not say that it is always one or always the other. You must consider the particular situation to figure this out.

The basic principle is that there must be IP connectivity between the source and the destination addresses.

Perhaps some examples might help. I have a customer that has a requirement that certain sensitive information will be transmitted from from one office to another office and must be encrypted by a site to site VPN with IPSec and GRE. Since the source and destination are both within their Enterprise network it works quite well to use private addressing for the source and destination addresses. I have another customer who uses site to site VPN with IPSec and GRE to go from one site to HQ over the Internet. For this it is a requirement that they use Public addresses for source and destination.

So the important thing is to consider whether the originating router can send a packet to the destination using private addressing and the other router can respond using private addressing and it gets to the originating router. In this case it is fine to use private addresses. Otherwise it is necessary to use Public addresses.

HTH

Rick

HTH

Rick

Okay I'm starting to understand as a public IP address that you may use themselves as the wan interface?

Review Cisco Networking for a $25 gift card