DC-DC Deployment Question

whistleblower
Getting noticed

DC-DC Deployment Question

Hi,

 

I´m planning a design where a customer wants to connect his branch offices to two different Datacenters (different IP-Subnets on both DC`s)! In the underlay 1x MPLS and 1x Internet circuit should be used!

 

I´ve been gone through the official documentation and every thing seems clear so far, BUT what I could`nt found is... how has the deployment to look when the traffic between the two datacenters should also use SD-WAN functionalites to spread traffic over the tunnels based on SD-WAN definitions? As my understand is, that is`nt possible when both DC use the MX in 1-armed Concentrator mode?!

https://documentation.meraki.com/MX/Deployment_Guides/Datacenter_Redundancy_(DC-DC_Failover)_Deploym...

5 Replies 5
Inderdeep
Kind of a big deal
Kind of a big deal

@whistleblower : did you saw this 

https://documentation.meraki.com/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/...

 

 

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com

hi @Inderdeep 

 

yes, of course I´ve looked through the documentation, but I was`nt able to find the information I`d need... 😞

If there`s a section that would describes the answer to my question and you know it - can you please point me to that?

Bruce
Kind of a big deal

@whistleblower if you have a one-arm VPN concentrator in both data centres then the best you can get is a single tunnel between them, one interface to one interface, so there really aren’t any policies that can be applied, it’s an all or nothing scenario. Whether the tunnelled traffic takes a MPLS path or an internet path will just depend on the routing of the outer IP address on the tunnelled traffic (I.e. how traffic is routed from MX A to MX B).

Inderdeep
Kind of a big deal
Kind of a big deal

@whistleblower : Check page number 32/33/34 below 

https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKCRS-2103.pdf 

 

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com
PhilipDAth
Kind of a big deal
Kind of a big deal

If each DC is a seperate L3 domain, then traffic will be spread based on the subnets advertised by the DC MX into AutoVPN.  Basically, it will depend on what subnet the client tries to access.

 

If you really want traffic to go to both DC over both DC MXs, then you'll need a link between the two DCs, ideally use BGP, and use two templates.  The first prefers MX1, the second prefers MX2.

 

This article covers most of the concepts:

https://www.willette.works/active-active-meraki-sd-wan-headends/ 

 

This article covers off using BGP:

https://documentation.meraki.com/MX/Networks_and_Routing/BGP 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels