Anyone setup an MX to function as a traditional MPLS router?

DennisS
Here to help

Anyone setup an MX to function as a traditional MPLS router?

Our overall SDWAN architecture won't be finalized for several months. In the meantime, can our traditional ISR routers be replaced with MXs? Southbound (LAN) connectivity to MS/Catalyst switches should be straightforward, it's the northbound dynamic WAN advertisements is what I'm not sure about.

 

The MPLS routers establish BGP adjacencies with the carrier PE to advertise local prefixes. Assuming the carrier has no problem supporting OSPF will the MX advertise local prefixes to the carrier PE? My concern is, they'll only advertise AutoVPN prefixes.

2 Replies 2
Bruce
Kind of a big deal

Not sure exactly how you plan to setup your MX, but if you are using it in NAT mode then it won’t support any routing protocols on the WAN interface. If you have it in VPN concentrator mode then the WAN interface will support OSPF or BGP, but this is used to pass routes to/from a data centre, not a carrier PE.

 

If you are using an MPLS link in a SD-WAN scenario then that link must have access to the internet, either via a breakout provided by the carrier, or through your own data centre. The MX doesn’t use a routing protocol, just a default gateway towards the carrier, and the carrier network doesn’t know anything about your internal networks, just the IP address of the WAN port on the MX. All the traffic between your internal networks is encrypted, and appears to go to and from the WAN IP addresses of the MX - the internal IP addresses are in the encrypted part, which the MX unpacks when it receives data.

 

This is actually one of the advantages of SD-WAN, your internal IP addressing is completely separate to the WAN addressing, and invisible to the carrier. So you can do what you want, and you don’t need to involve the carrier to change things (or advertise internal routes to them). The MXs take care of the routing through the encrypted tunnel.

 

Realised I just rambled on a bit, hope it makes sense 😀

Hi Bruce,

 

Makes perfect sense and confirms my findings based on my preliminary evaluation work with MX equipment. 

 

Thank you

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels