cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
438
Views
0
Helpful
3
Replies

pix 7.0 OSPF Dynamic Routing over VPN ?

jiangcy
Level 1
Level 1

How can setup OSPF Dynamic Routing over VPN ?pix vpn tunnel has not ip address.pix is only run ospf on physical interface,how to setup ospf?

3 Replies 3

gfullage
Cisco Employee
Cisco Employee

You're thinking of a GRE/IPsec setup in IOS. With a PIX you just set up the interface to be a point-to-point OSPF interface, then manually define the remote OSPF neighbour (the IPSec peer). You then just add a line to your crypto access-list that includes traffic between the two OSPF neighbours, that way you ensure the OSPF unicast traffic goes over the tunnel.

See http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_70/cref_txt/mr.htm#wp1423803 for details.

So I can not setup full-mesh vpn or spoke-and-hub vpn

if only use pix devices.

Another question,point-to-point OSPF neighbour's ip address is remote pix inside interface?

i mean not dvpn to setup full-mesh vpn