Hi experts, I am solution`ng a multi-tenant DCI between 2 x datacenters. One is the primary and other is the standby DC. We have a 10G fiber connecting them on a CSR router. The service provider will NOT be doing any routing or MPLS, they will just provide a 10G fiber and we will take care of all the routing and logical separation. The solution in my mind is as below -
- Use VRF per customer on the CSR.
- On the LAN connecting side of the CSR, there will be a sub-interface with dot1q trunking and on the WAN side a GRE tunnel interface. Both will be part of the same VRF.
- Use BGP address family "ipv4 vrf" to advertise the vrf specific routes over the tunnel interface. (the bgp peering will happen over the tunnel interface).
- Encrypting the whole piece globally on the CSR. The ACL to match the interesting traffic for encryption will something like "permit gre any any"
Has anybody tried this? Is this a valid design?