cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
568
Views
0
Helpful
2
Replies

IPSEC and routing protocols

farancci
Level 1
Level 1

Using IPSEC Why do we need to use GRE or transport mode for routing protocols.

2 Replies 2

d-garnett
Level 3
Level 3

Because most IGP Routing Protocols (i.e., eigrp, ospf) use Multicast for propagation (between neighboring routers) to build their IP Ruoting tables.

IPSec can forward multicast IP data, but GRE can.

Philip D'Ath
VIP Alumni
VIP Alumni

With IPSec you establish a policy that says encrpyt a packet when it goes from this adreess to that address, and send the packet to this remote IP address.

So things like broadcast and mulicast dont work, which many routing protcols need.

Additionally because the encrytion address range is statically declared the network doesn't respond well to changes in its topology (usually cauused by device or link failure).

GRE over IPSec looks like a simple point to point link. Routing protocls can use it, and can route around failures.

Generally I use IPSec for small networks, and GRE over IPSec for medium to large networks.