[FROG] NHRP without IPSec

John Korakis jkorakis at gmail.com
Thu Apr 12 16:33:04 EDT 2018


Hi Donald and Benson,

Thank you very much for your responses.
The link you shared is the only useful document I was able to find. I
followed the instructions and omitted the “tunnel protection” part as I
don’t need encryption. Unfortunately, the GRE tunnels do not work and debug
logs error messages regarding missing VICI profile.
Having read the last paragraph of the document about tight integration with
IKE, as well as the post below, I assumed that it might not be possible to
configure NHRP without IPSec, hence I posted the question here to make
sure.

The post I referred to earlier:
https://lists.quagga.net/pipermail/quagga-users/2017-June/014729.html

One thing to note is that I am trying to set up NHRP between FRR and A
cisco ASR router.

Thank you very much again!

John


On Thu 12 Apr 2018 at 21:09, Benson Schliesser <bensons at queuefull.net>
wrote:

> Hi, John.
>
> The documentation that Donald shared will probably be helpful. Note that
> NHRP needs some kind of underlying encapsulation (i.e. a tunnel) in order
> to be applicable. But it doesn't necessarily have to use IPsec. For
> example, GRE is a common choice (with or without IPsec).
>
> Cheers,
> -Benson
>
>
> On Thu, Apr 12, 2018 at 3:59 PM, Donald Sharp <sharpd at cumulusnetworks.com>
> wrote:
>
>> John -
>>
>> I'm not aware of anyone with operational experience around NHRP
>> currently.  That is not to say someone might be lurking here who has
>> done something with it.
>>
>> I can point you at:
>>
>> https://github.com/FRRouting/frr/blob/master/nhrpd/README.nhrpd
>>
>> Which appears to have a decent walk-thru of what is needed to be done.
>>
>> If it's incorrect or you discover something wrong, we would love to
>> help create a wiki or accept Pull Requests for improving the
>> documentation for NHRP.
>>
>> thanks!
>>
>> donald
>>
>> On Thu, Apr 12, 2018 at 11:35 AM, John Korakis <jkorakis at gmail.com>
>> wrote:
>> > Hi all,
>> >
>> > Are you aware of any way to configure NHRP without IPSec?
>> >
>> > Thank you in advance,
>> >
>> > John
>> >
>> > _______________________________________________
>> > frog mailing list
>> > frog at lists.frrouting.org
>> > https://lists.frrouting.org/listinfo/frog
>> >
>>
>> _______________________________________________
>> frog mailing list
>> frog at lists.frrouting.org
>> https://lists.frrouting.org/listinfo/frog
>>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.frrouting.org/pipermail/frog/attachments/20180412/cb1a877e/attachment.html>


More information about the frog mailing list