01-09-2021 08:28 AM
Hi everybody,
Please consider the following example:
Above we have:
1) Viptela controllers ( not shown ) controlling three vedeges, assume all vedges are allowed to talk to each other. All viptela vedges uses TLOC IP addresses to form IPSEC tunnels, so Vedge -NY uses 1.1.1.1 , Vedge-CA uses 2.2.2.3 and so on.
2) Let say Vedge-NY wants to establish IPSEC tunnel ( data plane) with Vedge-CA for VPN2 connectivity, Since Vedge-NY is using TLOCA and Vedge-CA is using TLOC B, are they still be able to form IPSEC tunnel, does TLOC have to match on both ends?
Thanks and have a good weekend!!
Solved! Go to Solution.
01-11-2021 06:18 AM
1) first of all the TLOC are not IPs....we could say that are only identificators
2)I think there's a misunderstanding about the SD-WAN concepts...just remember the next, a TLOC is composed by the System IP "Identificator", a Color and an encapsulation. Most of the times the encapsulation will always be IPsec, and the System IP is up to you...now what will differ is the color which is relevant per type of transport, for instance MPLS would be a private color and Internet a public color. The thing is that different colors can stablish IPsec tunnels (Data Plane) between them in case you want or deny them by setting the transport "Restrict" however you need to really understand the importance about the colors and their significance becuase in summary they are relevant whenever an IPsec tunnels will be created using post or pre-nated IPs.
01-11-2021 06:18 AM
1) first of all the TLOC are not IPs....we could say that are only identificators
2)I think there's a misunderstanding about the SD-WAN concepts...just remember the next, a TLOC is composed by the System IP "Identificator", a Color and an encapsulation. Most of the times the encapsulation will always be IPsec, and the System IP is up to you...now what will differ is the color which is relevant per type of transport, for instance MPLS would be a private color and Internet a public color. The thing is that different colors can stablish IPsec tunnels (Data Plane) between them in case you want or deny them by setting the transport "Restrict" however you need to really understand the importance about the colors and their significance becuase in summary they are relevant whenever an IPsec tunnels will be created using post or pre-nated IPs.
01-12-2021 05:30 PM
"The thing is that different colors can stablish IPsec tunnels (Data Plane) between them"
That answer my question.
Thanks!!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: