- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DC Design Approach
Reading the deployment and configuration guides, its recommended to deploy One-Armed VPN concentrator model for Hub site. What are the disadvantages if we deploy the MX in Routed Mode connected to Internet for a Hub location and to terminate VPNs ? I reckon there will be security issues as we expose it to internet but can't we use F/W rules to restrict traffic?
I am thinking below topology, is this a definite No for Hub sites ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Most of the time you deploy a VPN Spoke (MX) in Routed Mode and a VPN Hub (also a MX) in Concentrator mode.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Definitely not a definite No - particularly as shown (you only show part of the AutoVPN) 😁
But there may be other aspects of the wider solution - and particularly as it grows / develops - where you find one-armed VPN Concentrator better suited / more flexible.
One key aspect here is that, for Data Centre type environments, we generally build any new functionality for VPNC mode. A good example historically would be BGP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, I will keep in mind on any functionality diff b/w deployment modes
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I use routed mode 90% of the time.
You would probably would use One armed VPN concentrator mode if:
- You have an existing firewall.
- You have an HA Internet setup (using something like BGP failover)
- You have a layer 3 network core
- You need OSPF to exchange routes.
You would probably use routed/NAT mode if:
- You can plug the MX into more than one Internet circuit so the MX can provide Internet HA itself.
- You need to support clients behind the MX accessing the Internet, or you want to be able to apply Meraki group policies to those users.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Philip, I have deployed few in the routed mode and was wondering on VPNC mode as Meraki docs suggested as recommended mode for Hubs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Most importantly:
If you have 2 DC's in active active where you have overlapping IP address space.
You know in cases your VM's must be able to migrate between DC's and are probably using something like VXLAN between your DC's then you only have the option to use Concentrator mode because in routed mode you cannot have overlapping IP space.
