[c-nsp] policy routing and ipsec problem

jan gregor jan.gregor at chronix.org
Sat Oct 1 02:34:18 EDT 2005


Hello.

At one of our customers we have folloving setup.

	   	  ----------DMZ-------
		 /		       \
	        /Fa1			\ Fa4
             Router 1 -------------- Router 2
	     Fa2|     Fa0	   Fa3 	|
		|			|
		|			|
		|			|
		|			Lan
	     Internet
	        |
		|
		|
	  IPSec Clients

IPSec clients connect through IPSec to Lan with no problem (static
routes between Router1 and Router2). Now the customer wants to allow
IPSec connections to DMZ but through Router 2 (Internet -> Fa2 -> Fa0 -> Fa3 ->
Fa4). Is there a possibility to create a route-map to route all traffic
from clients to Router2? To which interface I have to apply route-map?


Best regards.

Jan Gregor



More information about the cisco-nsp mailing list