01-09-2021 08:28 AM
Hi everybody,
Please consider the following example:
Above we have:
1) Viptela controllers ( not shown ) controlling three vedeges, assume all vedges are allowed to talk to each other. All viptela vedges uses TLOC IP addresses to form IPSEC tunnels, so Vedge -NY uses 1.1.1.1 , Vedge-CA uses 2.2.2.3 and so on.
2) Let say Vedge-NY wants to establish IPSEC tunnel ( data plane) with Vedge-CA for VPN2 connectivity, Since Vedge-NY is using TLOCA and Vedge-CA is using TLOC B, are they still be able to form IPSEC tunnel, does TLOC have to match on both ends?
Thanks and have a good weekend!!
Solved! Go to Solution.
01-11-2021 06:18 AM
1) first of all the TLOC are not IPs....we could say that are only identificators
2)I think there's a misunderstanding about the SD-WAN concepts...just remember the next, a TLOC is composed by the System IP "Identificator", a Color and an encapsulation. Most of the times the encapsulation will always be IPsec, and the System IP is up to you...now what will differ is the color which is relevant per type of transport, for instance MPLS would be a private color and Internet a public color. The thing is that different colors can stablish IPsec tunnels (Data Plane) between them in case you want or deny them by setting the transport "Restrict" however you need to really understand the importance about the colors and their significance becuase in summary they are relevant whenever an IPsec tunnels will be created using post or pre-nated IPs.
01-11-2021 06:18 AM
1) first of all the TLOC are not IPs....we could say that are only identificators
2)I think there's a misunderstanding about the SD-WAN concepts...just remember the next, a TLOC is composed by the System IP "Identificator", a Color and an encapsulation. Most of the times the encapsulation will always be IPsec, and the System IP is up to you...now what will differ is the color which is relevant per type of transport, for instance MPLS would be a private color and Internet a public color. The thing is that different colors can stablish IPsec tunnels (Data Plane) between them in case you want or deny them by setting the transport "Restrict" however you need to really understand the importance about the colors and their significance becuase in summary they are relevant whenever an IPsec tunnels will be created using post or pre-nated IPs.
01-12-2021 05:30 PM
"The thing is that different colors can stablish IPsec tunnels (Data Plane) between them"
That answer my question.
Thanks!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide