cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
479
Views
5
Helpful
1
Replies

Centralized Firewall at HQ with 1 MPLS circuit

mflint
Level 1
Level 1

Have large enterprise customer (100 remote sites) who is migrating from frame-relay to MPLS. Have a need to route all Internet-bound traffic from the remote sites to the HQ site to use the central firewall/proxy system. The traffic then routes back to the MPLS provider (via DS3)across the same circuit to the Internet connection also provided by the provider. The provider does not want the customer router to enable MPLS functionality.

I understand that the recommended approach is to either use two circuits or two subinterfaces in order to route traffic properly with the provider.

Are there any other options?

1 Reply 1

romccallum
Level 4
Level 4

http://www.cisco.com/en/US/tech/tk436/tk428/technologies_configuration_example09186a00801445fb.shtml

http://www.cisco.com/en/US/tech/tk436/tk428/technologies_white_paper09186a00801281f1.shtml

The above links should provide you with the info you require. I would look at the second like as this looks like a better fit for yourself.