From: Edouard Zorrilla (ezorrilla@tsf.com.pe)
Date: Sat Mar 14 2009 - 23:44:16 ART
It says :
(10.0.0.100)Host1----R4--------[CLOUD]----------R3----Host2(10.3.3.10)
IPSec should only encript traffic between 10.0.0.100 (Host1) and 10.3.3.10
(Host2) and should not be encapsulated inside of IPSec.<------ !!!
The solution uses : GRE over IPSec. Good because packets are going fine inside
GRE and tunnel source and tunnel destination are tunnel interfaces.
My solution : IPSec using mode : transport, inside the config transform-set.
am I all right or maybe I am goinf bad this days ?
Regards
Blogs and organic groups at http://www.ccie.net
This archive was generated by hypermail 2.1.4 : Mon Apr 06 2009 - 06:44:05 ART