I’m planning a set up of 6 x MX450s configured as AutoVPN Hubs split across 2 separate 10Gbps bearers, 3 on each although I intend to cross connect on the alternate WAN port in the event of one of the bearers failing.
Both of the ISPs CPE only have a single SFP+ port and 1 of them only provides 5 useable IP addresses.
Would it be possible to create a separate network in Merkai and have a pair of MS450s connecting the 2 bearers to the 6 x MX450s in 2 separate VLANS running their own DHCP so all they all the MX450s are NAT’d to a single address per bearer?
Or is there a much better way if doing Thais?
Being able to NAT is pretty key as it means all the traffic from clients at spoke sites will
appear on the internet from only 2 public ally facing IP addresses which makes configuring the firewall of our externally provided RADIUS and DNS simple.