Multicast over IPSec Tunnels?

Multicast over IPSec Tunnels?

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Multicast over IPSec Tunnels? Whatever I Fear 04-28-2008
Posted by Whatever I Fear on April 28, 2008, 10:23 am
If you were  Registered and logged in, you could reply and use other advanced thread options
We have an IPSec tunnel required for a client to pass certain types of
traffic, but multicast must also be passed.

I stumbled across this from Cisco:

CSCdu87170
o IP multicast traffic cannot be sent over a Generic Routing
Encapsulation (GRE) tunnel if IP Security (IPSec) is configured on the
tunnel. Other routing protocols may continue to work normally.
o Workaround: Remove IP Security (IPSec) configuration from the tunnel
or send IP multicast traffic over a different unencrypted tunnel.

I want to confirm is this is the case? If so, is there a way that this
can be done? And if not, would the most logical option be to just make
a straight GRE tunnel without IPSec and how does one configure
Multicast dense-mode over a tunnel.

I believe you just enable "ip multicast-routing" and "ip pim dense-
mode" on each relevent interface correct?

I appreciate any thoughts, thanks!


Pure Networks
Posted by News Reader on April 28, 2008, 10:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Whatever I Fear wrote:
> We have an IPSec tunnel required for a client to pass certain types of
> traffic, but multicast must also be passed.
>
> I stumbled across this from Cisco:

"Where" you stumbled across it is relevant.

When I did a search for CSCdu87170, I found it first in a section titled
"Resolved Caveats—Cisco IOS Release 12.1(12)"

Resolved, as in "fixed".

http://www.cisco.com/en/US/docs/ios/12_1/relnotes/crossplatform/release/notes/121mcavs.html

Your platform (not stated), and the IOS release (not stated) you are
using are determining factors in whether a workaround is needed.

>
> CSCdu87170
> o IP multicast traffic cannot be sent over a Generic Routing
> Encapsulation (GRE) tunnel if IP Security (IPSec) is configured on the
> tunnel. Other routing protocols may continue to work normally.
> o Workaround: Remove IP Security (IPSec) configuration from the tunnel
> or send IP multicast traffic over a different unencrypted tunnel.
>
> I want to confirm is this is the case? If so, is there a way that this
> can be done? And if not, would the most logical option be to just make
> a straight GRE tunnel without IPSec and how does one configure
> Multicast dense-mode over a tunnel.
>
> I believe you just enable "ip multicast-routing" and "ip pim dense-
> mode" on each relevent interface correct?
>
> I appreciate any thoughts, thanks!
>

Best Regards,
News Reader

Posted by Whatever I Fear on April 28, 2008, 11:06 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Whatever I Fear wrote:
> > We have an IPSec tunnel required for a client to pass certain types of
> > traffic, but multicast must also be passed.
>
> > I stumbled across this from Cisco:
>
> "Where" you stumbled across it is relevant.
>
> When I did a search for CSCdu87170, I found it first in a section titled
> "Resolved Caveats=97Cisco IOS Release 12.1(12)"
>
> Resolved, as in "fixed".
>
> http://www.cisco.com/en/US/docs/ios/12_1/relnotes/crossplatform/relea...
>
> Your platform (not stated), and the IOS release (not stated) you are
> using are determining factors in whether a workaround is needed.
>
>
>
>
>
>
>
> > CSCdu87170
> > o IP multicast traffic cannot be sent over a Generic Routing
> > Encapsulation (GRE) tunnel if IP Security (IPSec) is configured on the
> > tunnel. Other routing protocols may continue to work normally.
> > o Workaround: Remove IP Security (IPSec) configuration from the tunnel
> > or send IP multicast traffic over a different unencrypted tunnel.
>
> > I want to confirm is this is the case? If so, is there a way that this
> > can be done? And if not, would the most logical option be to just make
> > a straight GRE tunnel without IPSec and how does one configure
> > Multicast dense-mode over a tunnel.
>
> > I believe you just enable "ip multicast-routing" and "ip pim dense-
> > mode" on each relevent interface correct?
>
> > I appreciate any thoughts, thanks!
>
> Best Regards,
> News Reader- Hide quoted text -
>
> - Show quoted text -



I see, thank you for pointing that out, I did not notice the
'resolved', I appreciate it

Posted by News Reader on April 28, 2008, 1:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Whatever I Fear wrote:
>> Whatever I Fear wrote:
>>> We have an IPSec tunnel required for a client to pass certain types of
>>> traffic, but multicast must also be passed.
>>> I stumbled across this from Cisco:
>> "Where" you stumbled across it is relevant.
>>
>> When I did a search for CSCdu87170, I found it first in a section titled
>> "Resolved Caveats—Cisco IOS Release 12.1(12)"
>>
>> Resolved, as in "fixed".
>>
>> http://www.cisco.com/en/US/docs/ios/12_1/relnotes/crossplatform/relea...
>>
>> Your platform (not stated), and the IOS release (not stated) you are
>> using are determining factors in whether a workaround is needed.
>>
>>
>>> CSCdu87170
>>> o IP multicast traffic cannot be sent over a Generic Routing
>>> Encapsulation (GRE) tunnel if IP Security (IPSec) is configured on the
>>> tunnel. Other routing protocols may continue to work normally.
>>> o Workaround: Remove IP Security (IPSec) configuration from the tunnel
>>> or send IP multicast traffic over a different unencrypted tunnel.
>>> I want to confirm is this is the case? If so, is there a way that this
>>> can be done? And if not, would the most logical option be to just make
>>> a straight GRE tunnel without IPSec and how does one configure
>>> Multicast dense-mode over a tunnel.
>>> I believe you just enable "ip multicast-routing" and "ip pim dense-
>>> mode" on each relevent interface correct?
>>> I appreciate any thoughts, thanks!
>> Best Regards,
>> News Reader- Hide quoted text -
>>
>> - Show quoted text -
>
>
>
> I see, thank you for pointing that out, I did not notice the
> 'resolved', I appreciate it

The particular document I referred too, stated it was resolved (Cisco
IOS Release 12.1(12)).

You need to determine whether your installed IOS release pre-dates the
fix, or not.

Best Regards,
News Reader

Similar ThreadsPosted
Number of IKE Tunnels and IPSec Tunnels April 11, 2007, 12:48 pm
IPSec tunnels through IOS with PAT and ACL January 6, 2006, 11:35 am
GRE and IPsec tunnels May 10, 2006, 3:39 pm
CISCO IPSEC TUNNELS WITH NAT January 26, 2005, 8:39 pm
PIX Multiple IPSEC Tunnels April 12, 2005, 12:47 pm
pix ipsec tunnels problem July 24, 2005, 12:04 pm
redundat ipsec tunnels with nat October 3, 2005, 2:26 pm
Dual IPSEC tunnels September 13, 2006, 6:07 am
cheap cisco with ipsec tunnels July 6, 2005, 11:16 am
IPSec tunnels + NAT overload + NAT static January 12, 2006, 10:01 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map