Solved

Route Priorities with Crypto Maps for duplicate destination networks, failover VPN

Posted on 2007-12-04
4
591 Views
Last Modified: 2012-05-05
Here is the scenario. We have a hub and spoke point-to-point T1 infrastructure to our remote offices, obviously converging at our HQ. We have brought in DSL connections to each remote office as well, and plan to offload HTTP traffic through the DSL. We also want to use this DSL connection for a Site-to-Site VPN back to HQ if/when the T1 fails.

We are using Cisco 2600-series routers for the T1 links. We want to purchase Cisco 871 routers for the remote offices to provide firewall/vpn services.

Our Cisco routers hosting the T1 connections talk to each other through EIGRP. We plan on using route redistribution for RIP so the Cisco 871 (default IOS doesn't do EIGRP) can get these routes when the T1 is up and route the appropriate traffic over it. When the T1 fails, the routes will dissappear from the RIP advertisements and the Cisco 871 will stop sending corporate traffic to the 2600 router and hopefully start to use its Crypto map to send that traffic. We want the VPN to be 100% idle until the T1 goes down, in fact, it would be best if the VPN never even dialed until it was needed.

Here is the question, when a crypto map exists for a certain destination network in a Cisco device, is it smart enough to NOT use the crypto map for that network when it is also receiving routes from a dynamic routing protocol for the same network? Can you set administrative distances on crypto traffic?
0
Comment
Question by:Lweighall
  • 2
  • 2
4 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 20407582
> when a crypto map exists for a certain destination network in a Cisco device, is it smart enough to NOT use the crypto map for that network
Actually, yes. There is no heartbeat or keepalive. The tunnel is never active unless and until there is actual traffic that meets the interesting traffic as you have defined by access-list.
Your plan is solid. You don't need to set administrative distances on crypto traffic because it will simply use the default route as long as there is no other learned route more specific.
0
 

Author Comment

by:Lweighall
ID: 20408037
Thank you for your response.

Just to be clear I'd like to throw a more direct question at you. On the same Cisco device there exists a crypto map/ACL for the 192.168.1.0/24 network, but it also has a route in its table for the 192.168.1.0/24 through a router on its subnet, it will always prefer the route in the table learned from the other router over its own Crypto ACL? If not, can I set it to?

Sorry for the redundancy here, I just want to be crystal clear.



0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 20408158
Yes, it will always prefer the more explicit route. Routes are always chosen by best match, not first match.
0
 

Author Closing Comment

by:Lweighall
ID: 31412705
Thank you.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now