North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Q: Sizes of Existing and Planned Fully Meshed IPSEC VPN (Tunnel Mode)

  • From: Joe Rhett
  • Date: Sat Nov 03 19:54:32 2001

> We have a Cisco IPSEC based VPN with over 110 edge routers
> in a full tunnel-mode mesh, mostly 'big hunking routers' with 
> average CPU utilization under 15 percent.     The VPN is
> controlled by a single organization, under centralized admin.
> 
> Are there larger fully meshed VPNs out there in ISP land?  
> 
> Are there any 'real-tangible issues' with a fully meshed VPN
> at the size we are talking (around 120  sites fully meshed)?
 
My god, your job is worse than mine ;-)

We have a fully meshed Cisco-VPN with half that many edge routers, and we
have more than 100 open bug reports with Cisco. Every single release they 
have shipped has an issue that means we can't run it in one or more sites.

We're back to doing something I swore I would never do after working in the
NavSea MAN -- running the very latest code in brave but futile hope that
they've fixed something. 90% of the supposed 'bug fixes' they give us break
something else.

With 110 peers fully meshed, you must have only a single access-list
entry per site AND not all your sites talk at the same time. Until very 
recently there was a hard cap on IPsec SAs that we kept slamming into
due to multiple access-list entries per site gives you (source+remote)^2
number of SAs...

-- 
Joe Rhett                                                      Chief Geek
[email protected]                                      ISite Services, Inc.