05-09-2012 09:21 AM
Hi everyone,
I'm trying to figure out the best way to setup GRE over IPSEC and provide HA for GRE.
I have attached a basic configuration file for the setup below
My Setup:
VENDOR ROUTER
|
|
|
ISP
|
|
CORP ASA
|
|
CORE
|
|
-----------------------------
| |
| |
ROUTER_B ROUTER_A
1) configure IPSEC tunnel between Vendor Router and VPN ASA
2) Configure GRE between Vendor Router and both Router_B and A
3) Run EIGRP on Vendor Router
4) If I loose Tunnel to Router_A traffic should route out Router_B
05-09-2012 11:24 AM
Yes, it will work.
Just increase the delay on the tunnel interface on RouterB, so that your internal EIGRP peer (i.e. EIGRP peer behid Router A and B) will use RouterA as primary and "B" as a backup, due to lower delay on RouterA.
thanks
Rizwan Rafeek
05-09-2012 12:31 PM
thanks Rizwan
I was thinking of modifying the delay on the tunnel to router B on the Vendor Router...
05-09-2012 12:53 PM
"I was thinking of modifying the delay on the tunnel to router B on the Vendor Router"
Yes that will make as well.
Thanks
05-09-2012 01:23 PM
Great Thanks!
One more thing.. would it make sense to make the Vendor router a Stub in EIGRP?
05-10-2012 06:27 AM
"One more thing.. would it make sense to make the Vendor router a Stub in EIGRP?"
Yes, as long as the Vendor fine with it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide