Sunday, October 28, 2018

Supporting Multiple Customer VPNs Through Single Router/Firewall?

Hi all,

I'm trying to figure out how to accomplish this through either hardware or software, but here's the gist:

We have multiple customers who may/may not need access to server resources located in our datacenter. We want to establish site-to-site VPNs to each of their locations, as well as have the ability for their employees to access resources via a remote VPN. However, some of our customers have overlapping subnets (i.e. 192.168.1.0/24). I was looking at using VRF to provide routing capabilities, but the documentation on VRF-aware IPSEC leaves a lot to be desired. Further, I'm not quite sure if we have to assign individual static IPs for each customer to connect to, or if there's a way to redirect their logins to the correct VRF.

Does anyone have experience doing something similar? If so, what hardware/software was it implemented on? I know it's possible since there are companies out there doing the same thing, but I can't find info on how to implement something similar.



No comments:

Post a Comment