cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
636
Views
5
Helpful
2
Replies

Satellite Office - Modern Branch Office

RS19
Level 4
Level 4

I am looking for a modern branch office network design.

Below are the key design criteria.

1) The branch office will be shared by multiple group company users.

      ex - There will be users from 3 group companies sharing the network. But they need to be logically separated. (Segmentation)

2) Each group company user will need to access their respective resources in their DC

3) Common Guest WiFi Internet Access is rquired

 

What is the ideal cost effective design for this. ?
Will SD-WAN fit into this requirement .

 

2 Replies 2

1) The branch office will be shared by multiple group company users.

      ex - There will be users from 3 group companies sharing the network. But they need to be logically separated. (Segmentation)

  • Assign a VPN to each Company. 
  • Create a subinterface network for each company and assign it to their designated VPN.

2) Each group company user will need to access their respective resources in their DC

  • If you DC is meshed with SD-WAN, just make sure their server at the DC is on the same VPN you assigned them at the remote office. If you can't do that, then you would need to Route leak the server into their VPN.
  • If the DC is not SD-WAN capable, then please provide how you are connecting to the DC.

3) Common Guest WiFi Internet Access is rquired

  • Create a Guest wireless VPN and it's own network/subinterface.

 

What is the ideal cost effective design for this. ?

  • Per location, you can get an ISR 4331, upgraded Memory, additional 6 port NIC (for multi-ISP support)  with 100M DNA license and support for around 13k-16k.


Will SD-WAN fit into this requirement

  • SD-WAN, regardless of vendor, is the way to go. 

Thanks. I understood.

In Data Center , we do have SD-WAN & it can be used as part of it.

I understand from the WAS perspective SD-WAN is the way to go as it also provides segmentation.

 

Regarding LAN side how similar segmentation is achieved  for different group companies.

Is VRF the only option or is there any other option at LAN side which needs to be considered for the design.

.