Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Helloin our WAN we have the following config:- star topology to HQ with IPSec VPNs over Internet from remote sites- in most cases HW is C1812/2811 and C2951 in HQ- we use GRE tunnels over IPSec and EIGRP as routing protocol- on tunnel interface at br...
Hellocurrently we have WAN built with IPSec VPN tunnels and GRE over it. IPSec tunnel peers are the WAN side HSRP virtual IPs. We'd like to balance the load between the two routers in locations and in HQ. Now HSRP activ nodes take all traffic and som...
Hi Everybodyrecently we had some performance issues with C2811 which caused us to do some lab testing. For testing we used also C1812. The results were quite surprising for us, as the C1812 appeared to be more efficient than C2811. Below you can see ...
HelloI have 2 C2811 ISRs runnning c2800nm-advsecurityk9-mz.124-15.T17.binand having on board:1 Virtual Private Network (VPN) ModuleMy question is: is it possible to enable IPSec stateful failover (or switchover, SSO) between these boxes?I'm quite con...
Hello EveryoneI have a Cisco ASA5520-K8 (asa821-k8.bin, VPN Plus license) on which I terminate remote users via Cisco VPN Client and also remote sites via S2S IPsec VPNs. ASA has only one Internet interface thus both "groups" of VPNs are terminated o...
Hello Peterit seems that it was a problem with cacti. After I updated this BW on tunnel and recreated the graph (updating only didn't help) in cacti averythings looks like it should. The plot from the tunnel overlays with the physical interface stati...
@Josephhow can I verify if fragments are not encrypted?@PeterI set up a new BW - let's give it a try.Regarding config:How is the route towards the tunnel destination address defined? Is it handled by the default route?No, there's also a static route ...
that's correct - F0 is only for tunnel traffic.I considered also the IPSec overhead but I didn't think it may be such a difference. basing on these cacti plots it's about 10 times more. Is there any easy way to verify how much traffic is the encrypt...