Re: [IPsec] New -00 draft: Creating Large Scale Mesh VPNs Problem

2011-11-11 Thread Frederic Detienne
NHRP is a generic protocol that converts overlay addresses in any address family into transport addresses in any address family. The protocol works over NBMA meaning that it can work over virtually anything (i.e. no exuberant requirements). There is a clean layer separation and NHRP does not

Re: [IPsec] New -00 draft: Creating Large Scale Mesh VPNs Problem

2011-11-11 Thread Mike Sullenberger
In this case we are effectively building an NBMA tunnel cloud. I.e. A bunch of spoke nodes connected to one or more interconnected hubs. Using NHRP to find end-points in order to build the cross tunnels makes sense. Once you have used NHRP to find the endpoint then you can use IKE/IPsec to