Hello,
Is it possible to create a Site-to-Site VPN over a MPLS network. (Not a MPLS VPN)
VPN-Router → MPLS-Router → → MPLS-Router → VPN-Router
Kind regards
glistal
Hello,
Is it possible to create a Site-to-Site VPN over a MPLS network. (Not a MPLS VPN)
VPN-Router → MPLS-Router → → MPLS-Router → VPN-Router
Kind regards
glistal
Yes - it’s literally happening right now as most providers are operating their internet network on an MPLS network.
Yes of course as long as the two VPN devices have IP connectivity. There is added overhead but also the added security of the traffic being encrypted with keys under your control
Yes, of course. Asuming all is correctly configured.
From the point of view of your MPLS network, is simply Ip packets to move from point A to point B. So long as the two extremes speak the same VPN protocols and the tunel is stablished, the routing from your VPN will not interfere with the MPLS routes.
There wont be any routing problems with this?
Nah, as long as the MPLS know where your VPN Tunnelendpoints are, this is working like a charm.
As with all implementations it depends on how you configure it, but in general no. the site MPLS router will probably have the full internal routing table, but you dont mind that as your VPN router will have the correct routes pointing into the tunnel. The mpls router act as underlay and will only route the ipsec packets to the destination, the rest of the mpls router’s routing table will not be used but its no harm. All your packets are already in the ipsec.
Ofcourse you can configure split tunnelling to have some packets out of the ipsec routed directly over mpls.
That’s right. We don’t know the details of your setup but some MPLS services include internet for example. In that case you would point specific subnets down the IPsec tunnels and the 0.0.0.0/0 down the MPLS.