04-29-2024 03:59 AM - edited 04-29-2024 04:00 AM
Hello guys,
Need some understanding about VPN0 vs sub-interfaces design.
.. at DC design point of view i have one traditional MPLS link connect directly to the sdwan, and one public internet that i want to pass through FW.
i know that is possible to have one physical link facing the LAN with multiple VPN/VFR, each one in it's own sub-interfaces / vfr definition. Placing the parent physical interface in the transport tab, and all the SVI in the Service tab.
So my question is, in the same physical link facing the FW, can i have all the service SVI's and add a SVI transport tunnel interface (public inet).??
It's possible.?? Anyone has had this challenge.? How you overcame.? Had some embarrassment.? Can i expect some problems.?
Thanks for sharing the knowledge.
RD
04-29-2024 07:18 AM
Hi,
yes, you can. But not recommended. In case of link failure, you will not only lose internet but also service side.
Recommendation for transport side: each transport should have its own link
Recommendation for service side: dual link with port-channel and different service VPN interfaces on different sub-interface.
Used above approach, works normal as expected and have redundancy both on service and transport side.
04-30-2024 09:10 AM
Hi Kanan,
Thanks for you reply.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide