Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

giving internet conenctiion through MPLS


remote router(MPLS)----(MPLS)Router---l3---pix--internet

The MPLS config is with the ISP.

My requirement is :

Is it possible to give internet connectivity to the remote end users through the pix that is on my end.

Is that a good idea?

Thanks in advance



Re: giving internet conenctiion through MPLS

Yes its possible to give internet access to your remote users provided default propogation towards the PIX and the return path routing is taken care of (toANDfro) to the PIX.

Your ISP will be ditributing the default to the remote ends for Internet.

Many enterprises have a centralized Internet Access policy. So in such cases this is the easiest which could be done to control Internet Access for your remote branches, provided you have ample bandwidth for other applications reserved.

Or the other option which is cost intensive would be, local Internet BW, with centralized security Policies with distributed enforcement.

So not much of a right or wrong, but a call considering and weighing the user access ease, attached with cost implications.



New Member

Re: giving internet conenctiion through MPLS


This is definitely possible. Depending on what routing protocol you are using over your MPLS network you can distribute a default route into the cloud from your L3 switch. You can then remove the default static routes (or replace with floating statics) from your remote MPLS routers.

We do this currently and it works well. It gives you centralized control, reporting, and filtering of Internet traffic for the rest of your sites in your enterprise. The only issues you may find are that if you are currently allowing these sites to access the Internet locally, performance maybe an issues. Take into account the latency that will be added now that the Internet traffic will traverse your MPLS network.

CreatePlease to create content