Encapsulating multicast traffic over an IPSEC tunnel in a specific topology
Posted on 2004-10-04
Hello. First time posting here.
Below is the topology of the relevant portion of my network:
PIX 506 --> Cisco 1721 --> Internet --> Cisco 1721 --> PIX 515
I'm trying to set up a VPN. I've succefully established a VPN tunnel and can communicate in both directions. However, I have a problem. I need to pass multicast traffic through this tunnel and this is not possible via a PIX-to-PIX tunnel. To allow this, I've been told I first need to encapsulate traffic with GRE (a function normally performed by routers). The problem I have is in my topology: my 1721 routers lay beyond my PIX firewalls, preventing me the ability to encaspulate the multicast traffic BEFORE it hits the PIX. I've spoken briefly with two Cisco engineers. One said it was impossible without a topology change and the other said he thought it was possible, but he couldn't offer advice beyond that.
Does anyone have advice on this?