Tuesday, July 16, 2019

Need to separate public/private traffic - MPLS or separate VRF?

Hello,

I am wondering what you guys suggest as the best solution to this. We have two datacenters geographically separated and we are going to start doing some replication between them. We currently have fiber between the datacenters, but all the traffic on the fiber is public internet as they are connected to our external routers and such. The traffic we want to replicate is all going to be private. Typically I don't like the idea of mixing public and private traffic over the same fiber, but I am wondering if I am being over cautious and that there is a secure way of doing it. I don't want to replicate this traffic over an ipsec tunnel because that'd be slow...

So my thoughts are this. I could make a separate VRF on the core switches and do all the routing for this in that instance, or I could set up MPLS between the datacenters and have all the private traffic go over that.

Is one more secure than the other? Advantages/disadvantages of one way or another? I am kind of leaning towards MPLS as it seems like the most secure option but I wanted a second opinion. I believe all of our stuff is licensed for MPLS so licensing isn't an issue.



No comments:

Post a Comment