Tuesday, December 17, 2019

Looking for help to avoid layer 2 strected vlan

So to keep the long story short, we are getting two EPL lines from a ISP we need to connect to another site which we have. Our datacenter is primarily just L2 with VPC running on the leafs. And i do not want to strect a layer 2 to another site to avoid any loops as you guys suggests.

I have tried to come up with 3 solutions and i'm looking for any improvement and the best way to do this.

A diagram of one solution can be found here: https://imgur.com/a/Zwaoh7a

At the customer site, we will deploy two routers in HSRP/VRRP and each one of them connects to each CPE from the provider. If we look at the datacenter site, there will be two firewalls running Active/Passive, each CPE will connect directly to each CPE in a full mesh, and then i want to run OSPF over the EPL line to have fast convergence.

The secound solution diagram can be found here: https://imgur.com/Q3C2KVA

So in here the customer site will remain the same, but at the datacenter i will connect each CPE to each Core/Spine switch in a lacp aggregation since they are running VPC, so in this way i have a full mesh layer 2, but again then i'm strecting a routed vlan all the way back to our core switch, which i guess you guys will not recommend?.

The third solution:

I do not have a diagram of the third solution. But in this solution, i would terminate each CPE to a pair of leafs switches "in the datacenter site" in a LACP aggregation since these Leafs also will be running VPC. I will then configure OSPF on these leafs switches and then peer with each router of the customer. But would this be a viable solution at all and is it recommended?

The IP address in the diagram is the network i will routing on.

Or what would the community suggest i do?



No comments:

Post a Comment