Wired

 View Only
last person joined: yesterday 

Expand all | Collapse all

best practise to interconnect campus and DC on the same location

This thread has been viewed 30 times
  • 1.  best practise to interconnect campus and DC on the same location

    Posted May 24, 2022 11:46 AM
    Hi 

    we are discussing internally the best practise of a design in case you have a campus and the DC on the same location
    campus exist off
    2 cores (in active-active or active-standby)
    access switches connected to each core
    in DC 
    2 cores  (in active-active or active-standby)
    server switches connected to each core
    so like this assuming the aggregation layer doesn't exist
     
    sorry for the wrong layout

    The question is how does the best practise describe you must interconnect these cores?
    I am not able to find it in the documentation or in best practises but I always learned it must be with layer 3 links.
    Layer 3 because with layer 2 interconnects or even if you use mlag, if a loop or layer 2 issue happens on the campus it will extend to the DC even if STP protection is configured.
    With layer 3, these issues/impact will remain on the campus and the DC, if possible to reach from outside, can continue to function.
    Can you please provide me your idea and preferably provide me some documents to support this statement?

    Thanks for the help


    ------------------------------
    Bart
    ------------------------------


  • 2.  RE: best practise to interconnect campus and DC on the same location

    MVP GURU
    Posted May 24, 2022 07:24 PM
    Shouldn't both topologies (DC and Campus) be mutually protected by means of a Firewall? just a question...

    ------------------------------
    Davide Poletto
    ------------------------------



  • 3.  RE: best practise to interconnect campus and DC on the same location

    Posted May 25, 2022 02:40 AM
    Hi

    in my view that is indeed a possibility if there are multiple locations but if there is only 1 location, i don't see an issue to have both behind the same firewall as 2 separated networks linked with eachother with layer 3 links.

    but if you see it differently, feel free to share

    ------------------------------
    Bart
    ------------------------------



  • 4.  RE: best practise to interconnect campus and DC on the same location

    MVP GURU
    Posted May 25, 2022 02:56 AM
    Hello Bart, absolutely. We are in a similar situation (probably simpler since we are dealing with a sort of "Multi-tenants DC inside a Campus" scenario where Campus necessarily uses the major part of DC Hardware infrastructure transparently, infrastructure that is shared between Campus and Tenants): our idea was to have two Cores (with a VSX Cluster on each side of the fence), both resiliently interconnected with a proper Cluster Firewall which duty is to keep Campus and DC separated, with the additional constraint that that very same Firewall will connect both DC and Campus to various ISPs (a thing I don't necessarily like because, that way, that Firewall Cluster become a SPoF not only for the Campus but also for the DC which hosts systems of various tenants, the most of them really unrelated to Campus).

    Basically we're in a sort of "ISP DC with Campus" - because we provide services to various different Customers - but the bigger of them is also the whole owner of the DC infrastructure, use it mainly and owns what I call the Campus on which DC services are consumed...maybe it's a common scenario...but, to simplify, for sure we're not within a typical "University where the University DC serves mostly the University Campus" model.

    Probably a Layer 3 interconnection will suffice but then ACLs on both sides should be correctly setup and maintained (not only to filter the necessary inter-VLANs communications at Core level on each side but also to filter necessary communications between VLANs belonging to Campus versus DC and vice-versa).

    ------------------------------
    Davide Poletto
    ------------------------------



  • 5.  RE: best practise to interconnect campus and DC on the same location

    Posted May 25, 2022 03:04 AM
    Hi Parnassus

    i do agree but in the discussion my colleagues want to use mlag instead of my layer 3.
    So you will use different VLANs to interconnect DC and campus. With a broadcast storm or STP loop the packets will stay in that VLAN but the CPU of the device can go to 100% making it impossible to function for any VLAN right?

    ------------------------------
    Bart
    ------------------------------



  • 6.  RE: best practise to interconnect campus and DC on the same location

    Posted May 25, 2022 02:58 AM
    FYI i see the pictures have been removed that i added but i hope this makes it a bit clearer how my design would look like.
    it is about the bold lines that my question goes if they have to be layer 2 or 3

    server switch                                server switch
         |                    \                      /               |
         |                      \                  /                 |  
         |                        \              /                   |
         |                          \          /                     |
         |                            \      /                       |
         |                               \/                          |
         |                              /  \                         |
         |                            /      \                       |
         |                          /          \                     |
         |                        /             \                    |
         |                      /                  \                 |
            core switch                     core switch
         |            \                      /               |
         |              \                  /                 |  
         |                \              /                   |
         |                  \          /                     |
         |                    \      /                       |
         |                       \/                          |
         |                      /  \                         |
         |                    /      \                       |
         |                  /          \                     |
         |                /             \                    |
         |              /                  \                 |
           core switch                                core switch
         |                    \                      /               |
         |                      \                  /                 |  
         |                        \              /                   |
         |                          \          /                     |
         |                            \      /                       |
         |                               \/                          |
         |                              /  \                         |
         |                            /      \                       |
         |                          /          \                     |
         |                        /             \                    |
         |                      /                  \                 |
          access switch                    access switch

    ------------------------------
    Bart
    ------------------------------



  • 7.  RE: best practise to interconnect campus and DC on the same location

    MVP GURU
    Posted May 25, 2022 03:08 AM
    A Routed interface (Layer 3) can be setup over a Multi-Chassis LAGs (VSX LAGs)...so I don't see necessarily an issue by resilinetly interconnecting VSX Clusters back-to-back and keep them as two separated Spanning Tree topologies.

    ------------------------------
    Davide Poletto
    ------------------------------