01-31-2013 05:41 PM - edited 02-21-2020 06:40 PM
Hi experts,
I haven't configured the VPN for a long time on the routers so I want your recommendation for best practice.
I need to run OSPF on top of it so it has to be GRE over IPSec
I googled and I see old type of config that I used to do with use of crypto map. Then I see config with Ipsec profile which is applied to the tunnel interface (tunnel protection). I also see on the manual about isakmp profile...
Is there a configuration example that you can provide? This is site to site VPN with most basic PAT on the interface for the remote office to surf Internet. My routers are fairly recent. One is 2821 with newest 12.4 T code and another is 2921 router.
Thanks,
Solved! Go to Solution.
02-01-2013 01:34 AM
Hi!
I didn't have one that exactly matched your needs, but I made one. I configured it by hand so there might be some config-errors.
01-31-2013 09:29 PM
I think this is what you need:
02-02-2013 01:21 PM
Thanks Andrew! I am reading the document and it is very helpful
02-01-2013 01:34 AM
02-02-2013 01:23 PM
Hey Henrik, you just did my work for me... Thanks a lot
One more question, MTU, TCP adjust on the tunnel interface, do you have the value handy? My Internet facing interface has MTU size of 1500 bytes
Thanks,
02-02-2013 02:41 PM
No problems
I'm not an expert at mtu-sizes, so I'm not the right person to ask, sorry.
02-02-2013 11:20 PM
Hello Difan,
the GRE overhead are 24 bits, so regular MTU ( 1500 less GRE overhead)
It will give us the rigth MTU size for your tunnel interface running GRE 1476
Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide