cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
515
Views
1
Helpful
2
Replies

SDWAN Design VPN0 - subinterface

rjds
Level 1
Level 1

Hello guys,

Need some understanding about VPN0 vs sub-interfaces design.

.. at DC design point of view i have one traditional MPLS link connect directly to the sdwan, and one public internet that i want to pass through FW.

i know that is possible to have one physical link facing the LAN with multiple VPN/VFR, each one in it's own sub-interfaces / vfr definition. Placing the parent physical interface in the transport tab, and all the SVI in the Service tab.

So my question is, in the same physical link facing the FW, can i have all the service SVI's and add a SVI transport  tunnel interface (public inet).??

It's possible.?? Anyone has had this challenge.? How you overcame.? Had some embarrassment.? Can i expect some problems.?

Thanks for sharing the knowledge.

RD

2 Replies 2

Hi,

yes, you can. But not recommended. In case of link failure, you will not only lose internet but also service side.

Recommendation for transport side: each transport should have its own link

Recommendation for service side: dual link with port-channel and different service VPN interfaces on different sub-interface.

Used above approach, works normal as expected and have redundancy both on service and transport side.

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

Hi Kanan,

Thanks for you reply.

 

Review Cisco Networking for a $25 gift card