I am trying to determine what would be the best way to encrypt our traffic on a private VPLS link between sites. We have 3 sites connected via VPLS by our ISP. All three sites have a Catalyst 3850 switch and currently have EIGRP configured. Site 1 will be the hub for this scenario so that all traffic leaving a remote site will go through site one to get anywhere it needs to get to. Sites 2 and 3 are spokes.
Initially the idea was to encrypt the traffic using MacSec but since these are switches and not routers, adding a third site raises some questions as subinterfaces are not available on the switches.
Site 1 --------------ISP VPLS -----------------------Site 2
Sites 2 and 3 have 250 Mbps connectivity each and Site 1 has 500 Mbps so we would have to rate limit.
Can MacSec work for this solution? Would a different approach be recommended?
Cisco SD-WAN Cloud OnRamp allows you to simplify and secure connectivity to cloud applications and public clouds. Interested in testing out the latest Cisco Cloud OnRamp solutions?
Sign up to try out various use cases with the Cisco SD-WAN Cloud ...
Please use the new link http://cs.co/CoR-Trial for Demo and updated guides.
Cisco SD-WAN Cloud OnRamp allows you to simplify and secure connectivity to cloud applications and public clouds. Interested in testing out the latest ...
“Catalyst 8500 Series - Deep Dive”
This event will have place on Tuesday 17th, November 2020 at 10hrs PDT
The Catalyst 8500 Series Edge Platforms are built with the highly programmable, third-generation Cisco Quantum Flow Processor and designed for ...
“Catalyst 8000 Edge Platforms Family Overview”
This event will have place on Wednesday 4th, November 2020 at 10hrs PDT
Designed for an intent-based networks, the Cisco Catalyst 8000 Edge Platforms family offers best-in-class networking and security ...
I'm currently redistributing OSPF to BGP and setting a local pref on the routes. Currently this works fine and having no issues. ip prefix-list ospf-routes seq 10 permit 172.16.100.0/24
route-map ospf-bgp permit 10
match ip address prefix-list ...