In article < .com>,
<> wrote:
>What if my networks are behind nat. Can I create crypto maps and set up
>the routing to go inside nat? does this make a difference? Can I do
>this with ibgp? Thanks
Not really clear what you are asking for... but if you need routing
through an IPsec tunnel or through a firewall doing NAT, your choices
are pretty much limited to either a GRE tunnel or BGP. My preference is
BGP, but a GRE tunnel can be easier. Either way, if you're routes are
going through a NAT translation, it's a bit tricky to get the
forwarding tables to be correct (the next hop advertised by the routing
protocol does not get translated by NAT, so you have to force it to be
correct. This is trivial with BGP, or can be done indirectly using a
static route.
Depending upon your environment, you may also need to worry about how
much you can trust the routes advertised on the other side of the
firewall. See the white paper on my web site on supporting redundant
firewalls for a paranoid example. You may also get some hints from the
redundant VPN white paper, also there.
Good luck and have fun!
--
Vincent C Jones, Consultant Expert advice and a helping hand
Networking Unlimited, Inc. for those who want to manage and
Tenafly, NJ Phone: 201 568-7810 control their networking destiny
http://www.networkingunlimited.com