Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Deployement Scenario for 10 sites with 2 links from each,1 link its MPLS VPN/2nd IPSec VPN

Hi Guys!

Plz Plz any Doc or white paper witch describe any Deployement Scenario for 10 sites with 2 link from each,1 link its MPLS VPN and the backup link IPSec Vpn to the H.O..

Thanks

2 REPLIES
Hall of Fame Super Silver

Re: Deployement Scenario for 10 sites with 2 links from each,1 l

Hello Alsayed,

the solution reference network design section of CCO can be of help

http://www.cisco.com/go/srnd

WAN section

http://www.cisco.com/en/US/solutions/ns340/ns414/ns742/ns817/landing_wan_security.html

I would suggest DMVPN for  IPSec backup links

see

http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/DMVPDG.html

L3 MPLS VPN enterprise consumer guide

http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/L3VPNCon.html

with 10 sites it is wise to use DMVPN instead of relying  on multiple point-to-point GRE tunnels over IPsec.

In any case I would suggest to have GRE layer and to not use IPsec directly so that you can use a dynamic routing protocol over the tunnel(s).

Some care is needed at central site to avoid to have secondary routes preferred over MPLS VPN sites:

if PE-CE protocol is eBGP the WAN edge router needs to redistribute into the IGP used in central site.

The DMVPN hub router should be a distinct device and should redistribute into the  IGP the routes learned over the DMVPN cloud.

To design correctly a different IGP has to be used on the DMVPN in order to create  a need for redistribution into central site IGP at DMVPN hub device. The seed metric of redistributed routes has to be higher then those used by MPLS WAN edge router in central site so that primary link over MPLS is used  until is alive.

At remote site if there is only one router and it has eBGP session with PE node and an IGP neighborship over the DMVPN for the lower AD of eBGP routes it prefers the MPLS path as desired.

To be noted that another dimension to be used in order to build the desired hierarchy of routes and paths is the use of route summarization over the secondary paths so that most specific routes over primary paths are used first if available.

Hope to help

Giuseppe

Community Member

Re: Deployement Scenario for 10 sites with 2 links from each,1 l

Thanks Giuseppe

254
Views
5
Helpful
2
Replies
CreatePlease to create content