The most effective way to do this I've seen so far essentially turns
your network inside out. The "Global" portion of the router is
management, in RFC1918 space, and your "internet/public"
IP's/traffic/etc are all carried in a dedicated VRF.

And there multicast (IPv4 and IPv6) came in ;)

Jerome

Taking a production network NOT designed that way, and doing the
inside-out... well.... that's every bit as hard as it sounds...


_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

--
-------------------------------------------------------------
Jerome Durand

Responsable des services aux usagers
Services operations & support manager

            Réseau National de Télécommunications
     pour la Technologie, l'Enseignement et la Recherche

Tel:    +33 (0) 1 53 94 20 40  |  GIP RENATER
Fax:    +33 (0) 1 53 94 20 41  |  c/o ENSAM
E-mail: [email protected]     |  151 Boulevard de l'Hôpital
http://www.renater.fr          |  75013 PARIS
--------------------------------------------------------------

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to