IPsec Hub and Spoke Topology

Author
Michaelwright1900
New Member
  • Total Posts : 2
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/08/28 11:46:24
  • Status: offline
2020/09/15 11:28:36 (permalink)
0

IPsec Hub and Spoke Topology

Hiya
I have been tasked with a project at work to create upto 3000 VPNs to remote devices. I have chosen to go with the HUB and Spoke topology because the remote devices will be using SIM cards and will be a mixture of 3rd party routers. We cannot use DDNS sa they are mobile devices and will have dynamic public IPs.
 
The HUB and Spoke topology should do the job. But there is a requirement by the department we are doing the work for; Due to the amount of IP subnet pools that would be needed for the remote devices(mixture of different customers). it has been requested we do not publish subnets from the remote devices, but we use the VTI (route based VPNs)and DST-NAT to the devices behind the remote routers(spokes). To do this we would need to know the VTI IP addresses on every VPN. 
 
Is this possible or am I wasting my time?
 
Mike
#1

1 Reply Related Threads

    emnoc
    Expert Member
    • Total Posts : 5769
    • Scores: 375
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: IPsec Hub and Spoke Topology 2020/09/15 22:34:08 (permalink)
    0
    Why?
     
    So if you are going to do dst-nat than you need to set and manage 3000x site DNAT which by that a alone would be a challenge.
     
    Does the 3000x device have services that the hub would ever connect to?
     
     
    Ken Felix

    PCNSE 
    NSE 
    StrongSwan  
    #2
    Jump to:
    © 2020 APG vNext Commercial Version 5.5