10 messages in net.nether.puck.cisco-nsp[c-nsp] PIX VPN Mesh w/ OSPF
FromSent OnAttachments
Dave BreilandJan 11, 2005 12:55 pm 
Jim McBurnettJan 11, 2005 1:29 pm 
Rodney DunnJan 11, 2005 2:12 pm 
su1drootJan 15, 2005 2:21 pm 
Joe MaimonJan 15, 2005 7:17 pm 
Rodney DunnJan 15, 2005 7:26 pm 
Dave BreilandJan 16, 2005 2:18 am 
Rodney DunnJan 16, 2005 10:10 am 
su1drootJan 16, 2005 2:54 pm 
lis...@hojmark.orgJan 16, 2005 5:17 pm 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:[c-nsp] PIX VPN Mesh w/ OSPFActions...
From:Jim McBurnett (ji@tgasolutions.com)
Date:Jan 11, 2005 1:29:46 pm
List:net.nether.puck.cisco-nsp

Dave, Do you have an internal router at each site? If you do use EIGRP on those routers and GRE tunnels. The EIGRP will pass traffic over the GRE and the dynamically route the data based on the VPN delay. This will be totally independent of the ISP status... I think I would use 2811 or 2801 VPN routers.... 2801 would be cheaper than the PIX anyway.. And give you other functions.....

Jim

-----Original Message----- From: Dave Breiland [mailto:supe@dynamicis.com] Sent: Tuesday, January 11, 2005 12:56 PM To: cisc@puck.nether.net Subject: [c-nsp] PIX VPN Mesh w/ OSPF

I want to make sure I'm on the right track and haven't set myself up for failure... I have 4 offices around the US. Each site has a different ISP... connected with a T1. My plan was to have a PIX-515 at each site. I would use the PIX's to create VPNs between each and every site. My guess is that there will be times that the ISPs will have routing issues between each other. To get around this, I would think that... -Route between Site A and Site B fails -Site B re-routes data to Site C which still has VPN to Site A. Presumably this would require EIGRP or OSPF. Unfortunately it looks like the PIX only supports OSPF. Is this the right direction/steps I should be taking? Am I just over complicating things? Has anyone had success with OSPF and the PIXs?

Thanks for any input.