cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1160
Views
0
Helpful
5
Replies

Layer-2 extension over Internet

Claudio Battan
Level 1
Level 1

I need to extend some VLANs between two location (the Enterprise DataCenter and a remote DR DataCenter).
The obvious solution is using OTV on two CSR1000v's.
The connection I have to use is the Internet, so the join-interfaces will be directly on the public network.
Question: is OTV traffic somehow "protected"?
Can I implement two IPSEC tunnels between the two CSRs and then pass the OTV traffic through this tunnel?
Is there any configuration example?
Thank you
Claudio

5 Replies 5

what is the Intra DC protocol you use is it VXLAN or it traditional DC?

Claudio Battan
Level 1
Level 1

NO VXLAN, only "traditional"

This is an insecure solution, as the GRE tunnel is not encrypted.
Also L2TP seems a bit obsolet, I would prefer to use OTV with CSR virtual routers

Maynor_33
Level 1
Level 1

very interesting , good job and thanks for sharing such a good blog.

 

MyCCPay

Review Cisco Networking for a $25 gift card