?
Solved

GRE over IPSec for DR

Posted on 2006-10-20
3
Medium Priority
?
459 Views
Last Modified: 2008-01-09
Scenario is as follows:

1 PIX that will be utilizing an IPSEC tunnel to an ASA at another site.

1 router behind the PIX needs to tunnel GRE to a router behind the ASA.  (for EIGRP routing updates)

This will be utilized in a DR scenario where our core connection goes away.

Any assistance in pointing me in the right direction is appreciated.  I know there are some issues routing GRE over IPSEC and I'd like to avoid them if possible.
0
Comment
Question by:NetAdmin5555
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 4

Accepted Solution

by:
periferral earned 2000 total points
ID: 17883533
I dont see why there would be a problem. Once an IPSec tunnel is established between the PIX and ASA, all traffic should just go through the tunnel. The router to router GRE should just work. If not,

try fixup pptp on the ASA device and you should be okay.
fixup pptp 1723
or
policy-map global_policy
 class inspection_default
  inspect pptp

0
 
LVL 1

Expert Comment

by:Computer101
ID: 20286670
Forced accept.

Computer101
EE Admin
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question