cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1935
Views
5
Helpful
3
Replies

EoIP mobility tunnel and FW rules

pallaruelo
Level 1
Level 1

Hello,

 

I have a question, which equipment initiates the data path EoIP tunnel between a corporate controller and a guest controller located in a DMZ ?

 

Main Controller (Trusted Zone) <----->Firewall ASA5505<----->Guest Controller (Untrusted Zone)

 

Thank you in advance for your answer.

Franck.

1 Accepted Solution

Accepted Solutions

Stephen Rodriguez
Cisco Employee
Cisco Employee

I agree with Rasika. Allow either side to send the traffic.

 

but IIRC, the lowest MAC address, per pair, is the one that initiates the EOIP tunnel.

 

HTH,

Steve

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

View solution in original post

3 Replies 3

I would open EoIP (IP protocol 97) and UDP 16666 in both directions.

HTH

Rasika

Hello Rasika,

 

That's I noticed too on the ASA5505.

 

Many thanks,

Franck.

Stephen Rodriguez
Cisco Employee
Cisco Employee

I agree with Rasika. Allow either side to send the traffic.

 

but IIRC, the lowest MAC address, per pair, is the one that initiates the EOIP tunnel.

 

HTH,

Steve

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered
Review Cisco Networking for a $25 gift card