Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

WAN Environment running IPSEC Encrypted Tunnel 1

Status
Not open for further replies.

Krelian

MIS
May 30, 2001
23
US
I have a general question. Our company has a corporate office Cisco 3640 running multiple encryted VPN tunnels to 7 regional offices with 2620s. We have just add a new office and we have a spare Cisco 2620 with a T1 interface and ethernet interface. But the IOS version of this spare router does not have the IPSEC encrytion feature set. I was talking to a consultant to see if we can setup a standard GRE tunnel with this spare router to the new office until we have the budget to purchase another one. I was told that within the WAN environment, all the routers must be configured to participate with encryption due to the encryption structure and layers desgined by Cisco.

So, is this true? And if so, is there a way to configure this to get around it from buying a new router with encryion feature set. We are running NAT with EIGRP within our WAN internetwork. Any help is greatly appreciated.

_h
 
alrighty, well I take it you don't have a CCO login on That would be the quickest and easiest solution to your problem, i.e. download the latest and greatest feature set that contains IPSEC for your 2620. If you guys have a bunch of Cisco's in your WAN it doesn't make a lot of sense to me that you wouldn't have been provided a CCO login with your contract. Please advise, in the meantime I would recommend slapping that baby in, granted you wouldn't be able to establish an encrypted VPN tunnel using IPSEC but at least you'd have IP connectivity to your remote office. I'm the Fanciest of the Fancy...INDEED
 
Pete,

Thanks for you reply. No, we don't have a CCO login account. Since we didn't deal with Cisco directly, and the VPN/WAN was pretty much setup by a consultant orginally, we were never given a CCO account. Right now, we're trying to do some of the configurations ourselves in house instead of involving the consultant.

From your post, it looks like it is possible to have a mixed WAN environment with IPSEC VPN tunnels to some offices and non encryted GRE tunnels to other offices, and we can pass IP traffic between offices with encryted tunnels to GRE tunnels. Is that correct?

_h
 
Telnet into one of your IPsec routers, set it up as a tftp server and download the image from the router.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top