cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
423
Views
0
Helpful
2
Replies

Creating redundant VPNs between concentrators and Routers.

ger.kirby
Level 1
Level 1

Hello,

recently for redundant VPN connections, I have been using GRE/IPSec and OSPF. Works very will - just configure the GRE tunnel and apply the IPSec profile to it, enable OSPF on the interface and thats it. Thats in an all router environment

A situation has arised were I have to use 2 concentrators (3015) at one end of the VPN and IOS routers (2651xm) at the other. Each router has a seperate ISP conenction .

Is there a dynamic way I can set the two tunnels with dynamic protocols. I see examples for using VRRP on the internal and external interface of the concentrator - I would have to create a VPN to each router and use policy routing and HSRP on the site with the two 2600s. Looks messey.

Is there a dynamic way I can have these two sets of equiptment (routers at one end, conc's at other) and have some dynamic failover between the site-to-site vpns.

Thanks

Ger

2 Replies 2

umedryk
Level 5
Level 5

Yes, VRRP should be able to provide this functionality

basically got this working - on the Concentrator side used the VRRP and on the router side used HSRP as the VPN endpoint with RRI - http://www.cisco.com/en/US/products/sw/iosswrel/ps5012/products_feature_guide09186a00800ed370.html

Mise le meas

Ger