BGP over IPsec VPN hopeful feature request

GIdenJoe
Kind of a big deal
Kind of a big deal

BGP over IPsec VPN hopeful feature request

Hi guys,

 

So I have been reviewing this Meraki document: https://documentation.meraki.com/MX/Site-to-site_VPN/BGP_routing_over_IPsec_VPN where the feature is explained.

As I understand it we finally have a semi route based solution where only one TS will be used for 0.0.0.0/0 and then use an eBGP session with the remote VPN peer over a tunnel subnet allowing for routing of local and autoVPN subnets to external networks.

 

The only disturbing thing I found with this is that the local MX will advertise ALL local VPN enabled networks in addition to the AutoVPN received iBGP routes which basically means your entire enterprise... and also inbound you will receive all the routes the peer sends you.  Since BGP is a trust based system...

Question 1:  Are there plans to make in and outbound filtering of routes available per BGP session?
Question 2: Does this work seamless with VPN subnet translation?
Question 3: Is there a way to filter outbound or inbound packets over the IPsec VPN?
Question 4: When will we finally have the ability to just use static route based VPN's and control which local subnets we announce to which peer? Both route based and policy based.

In essence: we need more control!

2 Replies 2
KarstenI
Kind of a big deal
Kind of a big deal

I admire you for still having hope for extranet VPNs.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
GreenMan
Meraki Employee
Meraki Employee

I know that route filtering for BGP is generally under consideration, but can't provide any specific details.   In the meantime, definitely apply VPN firewall rules - controls traffic leaving the MX:  https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings#VPN_Firewall_Rules

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels