cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
937
Views
0
Helpful
2
Replies

Viptella SDWAN : Question about Private Mpls Transport interface control connection and tunnel.

abdulwasay1218
Level 1
Level 1

I am trying to understand how could I possible make a control connection & tunnel over the private mpls link which is not publicly routable.   Below is the sample topology.

 

viptella-1.png

1.) Both vEdges has direct connection from PE Routers. 

 

 

I see that TLOC and tunnels are up over the internet link, but the MPLS IPSEC tunnel is not up, off course TLOC for that link is showing down.

 

My question is does control connection to vSmart is must  from every interface to form tunnels, in this case MPLS interface can reach other, is this not enough for Tunnel formation ? If not what is the best solution to be able to use both links ?

Please someone help me and clarify my doubts.

 

2 Replies 2

elesani
Cisco Employee
Cisco Employee

In nutshell, by default, a WAN interface can become a transport interface, only if there will be an individual route towards controllers by sourcing that interface. This approach can be ignored if you turn off "Control Connection" from interface feature template that you are using, however, the downside is that your branch will run on a single point of failure so if the internet connection goes down, you will lose your management and monitoring ability to your branch router! 

 

Maybe another solution would be for you to inject route towards your controller in your MPLS segment too. 

 

Hope that helped

Here is how I configured.

-------------

vEdge-1 :

------------

ge0/1 

Color: MPLS

Control Connection: off

tunnel Interface: On

---------------

ge0/0

Color: biz-inet

Control Connection: ON

tunnel Interface: On

 

################

 

-------------

vEdge-2 :

------------

ge0/1 

Color: MPLS

Control Connection: off

tunnel Interface: On

---------------

ge0/0

Color: biz-inet

Control Connection: ON

tunnel Interface: On

 

I still don't see tunnels being formed over mpls link. MPLS interfaces are reachable , I verified by pinging the interfaces ip sourcing from the mpls interfaces and allowing ICMP on those interfaces. 

 

Is there anything I am missing ??