07-30-2013 03:30 PM - edited 03-04-2019 08:36 PM
I have a project that requires 2 data centers, one for a hot standby. I have 5 remote offices that need to connect to data center 1. In the event data center 1 goes down then I need the 5 remote sites to connect to data center 2.
All 5 remote offices as well as the DATA centers will have 5525x ASA's behind the boundry routers. The boundry routers will have IP/ACL and stateful packet filtering. the internal FW will be packet inspection
Both data centers will have 2 seperate internet connections plus a replication link out the back between them.
I wanted to use a multisite MPLS GRE tunnel which would originate from each remote office. In the event a remote office couldn't get to a data center then it would attempt to connect to the other data center. Question to follow........
The 2 data centers would replicate over the back channel so they wouldn't require connectivity to each other out the front.
I will eventually add dual front end routers so HSRP will be running locally
Questions:
1. Is this the best design to go with? concerned the 5 tunnels over a ds3 would be to much, unless I can load balance
2. What is the mechanism that allows MPLS GRE tunnels to load balance and create failover.
3. Has someone seen a white paper or diagram that supports this?
4. Am I missing somthing I should be considering?
07-30-2013 06:23 PM
Hi,
Does DMVPN or something similar meet all requirements? You can have dual hub dual DMVPN to get active/stanby, and encryp traffic go through internet. What's the business case of running MPLS here?
Sorry about not answering your questions directly; just want to get clear on the use case. You can take a look the following link for MPLSoGRE
http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/ngwanearch.html#wp1000241
HTH,
Lei Tian
07-31-2013 07:21 AM
Business case for MPLS is voice ,T-1 and fault tolerance. I also need to prioritize traffic. I some traffic that is critical to receive at all times. I considered dual DMVPN just wasn't sure I could prioritize it correctly
07-31-2013 03:51 PM
You can apply QoS for DMVPN; you can prioritize voice traffic, and you can do per-tunnel QoS with DMVPN. However, you will lose control of the packets once packet gets in the internet, regardless the solution you are using.
HTH,
Lei Tian
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide