[c-nsp] MPLS VPN Running BGP w/ failover IPSec VPN Over Internet

Gert Doering gert at greenie.muc.de
Wed Jan 27 15:18:59 EST 2010


Hi,

On Wed, Jan 27, 2010 at 07:06:18PM +0100, Ivan Pepelnjak wrote:
> If I understood the original question correctly, he's an MPLS
> VPN customer running BGP with his Service Provider. Unless I'm
> mistaken, it's somewhat hard to run IGP on top of that, unless you
> build GRE or DMVPN tunnels over MPLS VPN first.

Oh.  In that case I wasn't reading properly, I was assuming L2 MPLS VPN 
links (ethernet over MPLS or similar), not L3 VPN.

Indeed, in that case it's better to use BGP for everything - but I'd
still use a single protocol both for the IPSEC and for the VPN links
instead of relying on EEM to react to "things" and change configs.

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             gert at greenie.muc.de
fax: +49-89-35655025                        gert at net.informatik.tu-muenchen.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 305 bytes
Desc: not available
URL: <https://puck.nether.net/pipermail/cisco-nsp/attachments/20100127/2193cd13/attachment-0001.bin>


More information about the cisco-nsp mailing list