Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: RE: L2L VPN redundancy for T1 link

RE: L2L VPN redundancy for T1 link

From: Stewart, John <johns_at_artesyncp.com>
Date: Wed, 20 Apr 2005 12:22:15 -0500

John Kougoulos wrote:
> How about connecting A & B L2L with a GRE over IPsec (terminating the
> GRE on the routers) ? This way all the routes to B site will go through
> the router instead of the firewall. (Ok, you'll lose some
> bytes for GRE encapsulation).

So this has the benefit of sending all of the L2L traffic through the
firewall, rather than bypassing it?

The T1 routers be a single point of failure, no?

I'm not quite sure what GRE buys us here. Wouldn't it be possible to build a
VPN tunnel via IPsec between the two routers, and pass the IPsec traffic
through the firewall (which would unfortunately need to do some NAT as we're
using private addresses internally on these routers)? Why GRE?

Thank you

johnS
_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Apr 20 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos