[j-nsp] Hub and Spoke VPN

joe lin jlin at doradosoftware.com
Mon Nov 10 09:35:14 EST 2003


Well,

if you had multiple Hubs in your hub and spoke VPN.  you wouldn't be able to
inject the default.

Altho, I haven't seen any deployment of such topology yet...

-Joe
----- Original Message ----- 
From: "Pedro Roque Marques" <roque at juniper.net>
To: "Joe Lin" <jlin at doradosoftware.com>
Cc: "'Krzysztof Maj'" <mkrzych at post.pl>; <juniper-nsp at puck.nether.net>
Sent: Friday, November 07, 2003 4:24 PM
Subject: RE: [j-nsp] Hub and Spoke VPN


> Joe Lin writes:
>
> > In 6.0+ can you shed some light regarding to the use of logical
> > router or other hackeries to loop routes around?
>
> You need a "router" to append something to the as-path in order to do
> loop avoidance...
>
> One could configure an LR for this purpose. Add a logical tunnel
> interface pair between the main guy and the LR and loop routes that
> way, via peering through the LR.
>
> I haven't tried this myself so i don't have configs but it should be
> doable.
>
> Still, back to hub and spoke, do you really need to reflect spoke
> routs back to other spokes ? shouldn't you be able to aggregate them
> and/or inject a default at the hub ?
>
>   Pedro.
>
>




More information about the juniper-nsp mailing list