cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
686
Views
0
Helpful
3
Replies

Confused on certain aspects of Viptela Sd-wan...

m1xed0s
Spotlight
Spotlight

Can I ask someone with better understanding of sad-wan help on following confusion points?

 

  1. Does service VPN# have to match between sites? For example, there is one DC and one branch connected by the SD-WAN fabric. DC vedge is configured with VPN 10 represents the DC LAN. In order for branch to access DC lan over SD-WAN, is branch vedge must be configured with service VPN 10 as well?

  2. Marketing material emphasizes the traffic segregation feature in the viptela SD-WAN solution. But this segregation is only applicable within the SD-WAN fabric, right? Once traffic exits out vedge on LAN side, the segregation would depend on LAN setup (whether firewall or ACL on core device) if any, right? If LAN side just provides plain routing/switching, then traffic would be able to communicate...Am I wrong?

  3. Comparing with the traditional IPSec site to site VPN tunnel, what would be the benefit of SD-WAN, assuming there is only one Internet transport link per site/location and no office365/Azure?

3 Replies 3

1. If both are using same VPN they will communicate by default. If not, you need to create an extranet policy (similar to vrf route leaking) to communicate between DC and Branch.

2.Your understanding is correct.

3. You would get the benefit of FEC and packet duplication feature (check 19.1 release notes below)

https://www.cisco.com/c/en/us/td/docs/routers/sdwan/release/notes/xe-16-11/sd-wan-rel-notes-19-1.html

 

Regards,

Srikanth

Thanks!

3. Don't forget that with SD-WAN you can also build arbitrary topology over one WAN link. e.g. traffic engineering over particular site and service chaining. It's not possible or will be too complicated with just traditional ipsec.