Building a VPN WAN simulation between 4 sites and an HQ

DKolev
New here

Building a VPN WAN simulation between 4 sites and an HQ

Hey, to keep it short, I've been given a practice exercise to build a small scale WAN simulation between an HQ and 4 branch sites secure tunneling and redundancy. SD-WAN and VPN servers are off the table, so are application based VPNs. I can only use Cisco routers and configure them manually. 1 ISP, 100Mbps. What WAN design would you recommend? Should I use MPLS or IPSec? BGP or OSPF?

Any pointers are appreciated.

3 Replies 3
FannyLow
Here to help

MPLS will be provide you hub and spoke design with OSPF which is something like SDWAN design. However, IPSec will be point-to-point. 

 

Hope this can help. 

DKolev
New here

Would you say MPLS is necessary here or I can do it perfectly fine with L2TP?

PhilipDAth
Kind of a big deal
Kind of a big deal

This would be a better question for the Cisco Community, which deals with IOS-XE routers.

https://community.cisco.com/ 

 

If each site already has an Internet connection, I would use old-school DMVPN.

If you can install new circuits then MPLS is particularly simple.  You probably wont need any routing protocol, because the MPLS provider will do everything for you.  You would only need static routes.

 

You could also use point to point VTI tunnels over Internet connections, which uses IPSec under the hood.  I would still personally use static routes, as IMHO, dynamic routing is not warranted for such a small netwokr with no redudancy.  Otherwise I would use RIPv2 or EIGRP.  Much simpler than BGP or OSPF.

Get notified when there are additional replies to this discussion.