Wednesday, July 24, 2013

GRE Tunnel between Hub & Spoke with BGP Failover at Spoke Site

This is one small topology that I am going to put in production in few days. Below given is the In-House implementation.

There’s this one client & they are in need of a 10 Mbps VPN circuit between their H.O. & a new spoke site with in the same city. Two Metro Fiber circuits with Ethernet hand off are going to be deployed at the spoke site while the H.O. is already connected with the ISP over Metro Fiber. Both offices are going to be connected to the same PE router of the ISP.
BGP failover is required at the spoke site & Juniper SSG5 is going to be used for the purpose. The client will by-pass the ISP hops via configuring GRE Tunnel between their 2 offices.

Gear Used:
CLIENT-HO --> Cisco 851
ISP-PE --> Juniper SSG5
Client-Spoke --> Juniper SSG5 (To use it as a router, configured all interfaces in same zone)

Network Diagram:















Configuration Files:




No comments:

Post a Comment