Re: [OSL | CCIE_Security] OT:GETVPN Enquiry KS

From: ehtesham ali <conect2ehtesham_at_gmail.com>
Date: Mon, 22 Nov 2010 20:46:43 +0300

r1--->r2----r3

r1 and r3 got certs from r2 for ipsec among them
r2 is a ca server router , can it participate in ipsec vpn with r1 or r3
with preshared or rsa .??

On Mon, Nov 22, 2010 at 8:35 PM, Bruno <bruno.gimenez_at_gmail.com> wrote:

> That is what I understood as well. Once in the past, I tried to use the KS
> as GM but it didn't work to me
>
> On Mon, Nov 22, 2010 at 3:24 PM, karim jamali <karim.jamali_at_gmail.com
> >wrote:
>
> > Dear Gents,
> >
> > I have a real world implementation regarding GET VPN & I would need some
> > expertise help to confirm what I believe I understood. In a GET VPN
> > scenario, the KS only provide KS functionality, i.e. the KS itself cannot
> be
> > a GM subscribed to the KS and thus we have to dedicate one router or
> maybe
> > two for redundancy for KS functionality apart from all the other routers
> as
> > GM. Is this correct? Please if it is not I would appreciate if you will
> > correct me.
> >
> > Thanks
> >
> > Regards,
> > --
> > KJ
> >
> > _______________________________________________
> > For more information regarding industry leading CCIE Lab training, please
> > visit www.ipexpert.com
> >
> >
>
>
> --
> Bruno Fagioli (by Jaunty Jackalope)
> Cisco Security Professional
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html

Blogs and organic groups at http://www.ccie.net
Received on Mon Nov 22 2010 - 20:46:43 ART

This archive was generated by hypermail 2.2.0 : Sun Dec 05 2010 - 22:14:56 ART