<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Minimalistic GET VPN Example</title>
	<atom:link href="http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/</link>
	<description>Helping you become a Cisco Certified Internetwork Expert</description>
	<lastBuildDate>Tue, 07 Feb 2012 02:21:38 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Blog Post Catalogue &#124; CCIE Blog</title>
		<link>http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/#comment-139575</link>
		<dc:creator>Blog Post Catalogue &#124; CCIE Blog</dc:creator>
		<pubDate>Tue, 21 Sep 2010 12:56:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=2832#comment-139575</guid>
		<description>[...] A Minimalist GET VPN Example [...]</description>
		<content:encoded><![CDATA[<p>[...] A Minimalist GET VPN Example [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: peter</title>
		<link>http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/#comment-108528</link>
		<dc:creator>peter</dc:creator>
		<pubDate>Tue, 04 May 2010 15:27:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=2832#comment-108528</guid>
		<description>Good stuff  !</description>
		<content:encoded><![CDATA[<p>Good stuff  !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian</title>
		<link>http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/#comment-96372</link>
		<dc:creator>Adrian</dc:creator>
		<pubDate>Fri, 26 Feb 2010 06:36:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=2832#comment-96372</guid>
		<description>Hi, quick question:

So if I use just one Member Server there is NO way, the KEY server is able to encrypt/decrypt user traffic ? They just provide ipsec policies? Thanks.</description>
		<content:encoded><![CDATA[<p>Hi, quick question:</p>
<p>So if I use just one Member Server there is NO way, the KEY server is able to encrypt/decrypt user traffic ? They just provide ipsec policies? Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anon</title>
		<link>http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/#comment-88296</link>
		<dc:creator>Anon</dc:creator>
		<pubDate>Fri, 08 Jan 2010 03:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=2832#comment-88296</guid>
		<description>Just looking at this, if either site fails you will lose connectivity to the other as well? 

i.e. In a small business environment where potentially only 3-10 locations backing onto a private WAN/MPLS cloud. 

In smaller environments you wouldn&#039;t have the extra routers to act as a dedicated KS so they will double as GM in this sort of setup. 

Given that for RtrA to be a GM, it needs to register to RtrB and vice versa it seems GetVPN is actually reducing redundancy in that scenario. 

Only way around it I can think would be to have at least 3 KS operational so a single site failure does not bring down two sites.</description>
		<content:encoded><![CDATA[<p>Just looking at this, if either site fails you will lose connectivity to the other as well? </p>
<p>i.e. In a small business environment where potentially only 3-10 locations backing onto a private WAN/MPLS cloud. </p>
<p>In smaller environments you wouldn&#8217;t have the extra routers to act as a dedicated KS so they will double as GM in this sort of setup. </p>
<p>Given that for RtrA to be a GM, it needs to register to RtrB and vice versa it seems GetVPN is actually reducing redundancy in that scenario. </p>
<p>Only way around it I can think would be to have at least 3 KS operational so a single site failure does not bring down two sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anantha Subramanian Natarajan</title>
		<link>http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/#comment-80989</link>
		<dc:creator>Anantha Subramanian Natarajan</dc:creator>
		<pubDate>Tue, 24 Nov 2009 19:20:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=2832#comment-80989</guid>
		<description>Thank you petr for the article .....

Regards
Anantha Subramanian Natarajan</description>
		<content:encoded><![CDATA[<p>Thank you petr for the article &#8230;..</p>
<p>Regards<br />
Anantha Subramanian Natarajan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SecLearner</title>
		<link>http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/#comment-80776</link>
		<dc:creator>SecLearner</dc:creator>
		<pubDate>Mon, 23 Nov 2009 23:34:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=2832#comment-80776</guid>
		<description>Would have preferred a small topology diagram. Are R4 and R5 connected using 173.1.45.x? I used the topology that came with the VOD and I think I put the GETVPN_MAP in the wrong interface. I could not see the traffic go through the VPN and saw ping timeouts.

Otherwise, please keep them coming. I love it.

SecLearner.</description>
		<content:encoded><![CDATA[<p>Would have preferred a small topology diagram. Are R4 and R5 connected using 173.1.45.x? I used the topology that came with the VOD and I think I put the GETVPN_MAP in the wrong interface. I could not see the traffic go through the VPN and saw ping timeouts.</p>
<p>Otherwise, please keep them coming. I love it.</p>
<p>SecLearner.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tacack</title>
		<link>http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/#comment-80645</link>
		<dc:creator>Tacack</dc:creator>
		<pubDate>Mon, 23 Nov 2009 06:13:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=2832#comment-80645</guid>
		<description>Great article Petr. Always a fan! :)</description>
		<content:encoded><![CDATA[<p>Great article Petr. Always a fan! <img src='http://blog.ine.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fonesurj</title>
		<link>http://blog.ine.com/2009/11/21/minimalistic-get-vpn-example/#comment-80569</link>
		<dc:creator>fonesurj</dc:creator>
		<pubDate>Mon, 23 Nov 2009 00:36:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=2832#comment-80569</guid>
		<description>We have deployed close to 1000 sites on GET.  It is really important you follow the GET deployment guide.  We have run into a number of scenarios that cause get to fail.  The deployment guide compensates for most of these.

Also, if you are using anything before 12.4(15)T9, then you MUST have the GMs use the local loopback as their peer point, or GET will not recover after a circuit bounce.</description>
		<content:encoded><![CDATA[<p>We have deployed close to 1000 sites on GET.  It is really important you follow the GET deployment guide.  We have run into a number of scenarios that cause get to fail.  The deployment guide compensates for most of these.</p>
<p>Also, if you are using anything before 12.4(15)T9, then you MUST have the GMs use the local loopback as their peer point, or GET will not recover after a circuit bounce.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

