cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Cisco Community Designated VIP Class of 2020

147
Views
0
Helpful
0
Replies
Highlighted
Beginner

Multi-tenant DCI using encrypted GRE tunnels?

Hi experts, I am solution`ng a multi-tenant DCI between 2 x datacenters. One is the primary and other is the standby DC. We have a 10G fiber connecting them on a CSR router. The service provider will NOT be doing any routing or MPLS, they will just provide a 10G fiber and we will take care of all the routing and logical separation. The solution in my mind is as below -

- Use VRF per customer on the CSR. 

- On the LAN connecting side of the CSR, there will be a sub-interface with dot1q trunking and on the WAN side a GRE tunnel interface. Both will be part of the same VRF.  

- Use BGP address family "ipv4 vrf" to advertise the vrf specific routes over the tunnel interface. (the bgp peering will happen over the tunnel interface).

- Encrypting the whole piece globally on the CSR. The ACL to match the interesting traffic for encryption will something like "permit gre any any" 

 

Has anybody tried this? Is this a valid design? 

Everyone's tags (3)
CreatePlease to create content
Content for Community-Ad
FusionCharts will render here