cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2307
Views
0
Helpful
3
Replies

EIGRP over IPSEC

abbas.ali
Level 1
Level 1

Is it true that in order to run EIGRP between site-to-site VPN, One must need to run GRE because what I read that IPSEC doesn't support multiprotocol?

But then, my headqurter has PIX Firewall, where I was thinking of terminating 8 IPSEC tunnels from the remote offices. What I read that PIX Firewall and VPN Concentrators don't support GRE. Is there any alternatives.

3 Replies 3

Nairi Adamian
Cisco Employee
Cisco Employee

You can terminate the ipsec tunnel on the pix but you still need to have a router behind the pix to terminate the GRE tunnel.

something similar to the sample configuration below:

http://www.cisco.com/warp/public/707/gre_ipsec_ospf.html

hope this helps,

-Nairi

lnthompson
Level 1
Level 1

We build the GRE to the MSFC's on the 6500 inside the firewall. It works quite well as the previous post mentioned.

Neil Anderson
Level 1
Level 1

GRE is needed as IPSec does not support multicast needed for dynamic routing protocols such as EIGRP.

Depending on your remotes and routing plan, Reverse Route Injection (RRI)may be an option if you don't need to run "full" dynamic routing on both endpoints. RRI is available on IOS VPN Routers and VPN3000 Concentrator.

Also, PIX Firewall is OK as a site-to-site VPN head-end, however IOS VPN Router at head-end more readily supports hub-and-spoke/site-to-site VPN topologies, especially when spoke-to-spoke traffic is required.

Review Cisco Networking for a $25 gift card