cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
326
Views
0
Helpful
0
Replies

Multi-tenant DCI using encrypted GRE tunnels?

sandevsingh
Level 1
Level 1

Hi experts, I am solution`ng a multi-tenant DCI between 2 x datacenters. One is the primary and other is the standby DC. We have a 10G fiber connecting them on a CSR router. The service provider will NOT be doing any routing or MPLS, they will just provide a 10G fiber and we will take care of all the routing and logical separation. The solution in my mind is as below -

- Use VRF per customer on the CSR. 

- On the LAN connecting side of the CSR, there will be a sub-interface with dot1q trunking and on the WAN side a GRE tunnel interface. Both will be part of the same VRF.  

- Use BGP address family "ipv4 vrf" to advertise the vrf specific routes over the tunnel interface. (the bgp peering will happen over the tunnel interface).

- Encrypting the whole piece globally on the CSR. The ACL to match the interesting traffic for encryption will something like "permit gre any any" 

 

Has anybody tried this? Is this a valid design? 

0 Replies 0
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card