VMware Networking Community
pahenson
Contributor
Contributor

OSPF via Site-to-Site IPSec VPN

Good day all,

Is it possible to peer NSX with an OSPF neighbor through an IPSEC VPN site to site connection? The neighbor would be the next hop through the VPN.

The scenario is a Cisco router(VPN) -->L2 switch backbone --> (VPN)NSX Edge.

Cisco routers will pass the routing protocol multicast packets through the VPN, will the NSX Edge do the same???

Thank you...

Phil

Tags (4)
0 Kudos
6 Replies
nickmuir
Contributor
Contributor

Phil,

The Site-to-Site VPN capability of NSX does not support dynamic routing protocols

Nick

burnyd
Contributor
Contributor

Not that I am suggesting doing this but you can run a L2VPN on your physical network for both ESG's?  What are you trying to accomplish?

pahenson
Contributor
Contributor

There is a layer 2 network between the NSX edge and the perimeter router(VRF). The layer 2 network is not in my group's control, so we need to encrypt the traffic between the router/edge(vlan separation is not enough). I wanted to peer the NSX edge and router using OSPF. 

0 Kudos
SRoland
VMware Employee
VMware Employee

You may also configure password or md5 has for the OSPF if its through 3rd-party network:

http://pubs.vmware.com/NSX-61/index.jsp#com.vmware.nsx.admin.doc/GUID-6E985577-3629-42FE-AC22-C4B56E...

0 Kudos
pahenson
Contributor
Contributor

SRolandSRoland... The problem is not with OSPF authentication/hashing. ALL data needs to be encrypted across the L2 segment with an IPSEC/L3VPN tunnel.

0 Kudos
SRoland
VMware Employee
VMware Employee

OK. My bad. did not get the requirements completely. I would just repeat then the above ppl....

0 Kudos