[AusNOG] Fwd: multi customer self manageable virtual router
David George
davidg at oztix.com.au
Sun Apr 28 10:49:46 EST 2013
I know, it's a bit of a funny requirement... I'm just looking at the exercise at the moment and am under the impression that there must be a better way than how it's currently build.
The thing here is to give the customer the ability to manage *some* of their own stuff via a "user friendly" ui (sorry, mustn't have been clear on that one, definitely not for the network operators).
After reading my own post... I'm starting to think the best way to go about this is to put something together that can batch some config changes to whatever will do the vrf, at least then it'll be done properly on that device, and if the only lines being added are scoped to their wan ip and their vrf, even if the "user friendly" ui isn't awesome, it won't affect the performance and stability of the network, similar to how some cloud providers do it with ACE.
From: ausnog-bounces at lists.ausnog.net [mailto:ausnog-bounces at lists.ausnog.net] On Behalf Of Skeeve Stevens
Sent: Sunday, 28 April 2013 10:39 AM
To: <ausnog at lists.ausnog.net>
Subject: [AusNOG] Fwd: multi customer self manageable virtual router
George,
I don't think what you want exists. And a friendly Web UI? Really?
If there is something, it probably wont be very enterprise grade.
Cisco and Juniper both do the whole VRF thing very well, but not so scalable on the NAT side... ASR1K or MX5 to start. Maybe with a SRX for the NAT side.
They all have web interfaces... but really?
...Skeeve
Skeeve Stevens - eintellego Networks Pty Ltd
skeeve at eintellegonetworks.com<mailto:skeeve at eintellegonetworks.com> ; www.eintellegonetworks.com<http://www.eintellegonetworks.com/>
Phone: 1300 239 038; Cell +61 (0)414 753 383 ; skype://skeeve
facebook.com/eintellegonetworks<http://facebook.com/eintellegonetworks> ; linkedin.com/in/skeeve<http://linkedin.com/in/skeeve>
twitter.com/networkceoau<http://twitter.com/networkceoau> ; blog: www.network-ceo.net<http://www.network-ceo.net/>
[http://eintellegonetworks.com/logos/ein09.png]
The Experts Who The Experts Call
Juniper - Cisco - Cloud
On Sun, Apr 28, 2013 at 10:31 AM, David George <davidg at oztix.com.au<mailto:davidg at oztix.com.au>> wrote:
Morning all,
Does anyone know if a product exists that can allow me to act as a gateway for a bunch of different private l3/l2 networks with overlapping ips... so it'll have to understand multiple route tables or vrf at some level (still need each customer isolated, although each customer can have multiple sites)... and give the customers the ability to manage their own ipsec tunnels, port forwards and anything else they're likely to want via a friendly web ui ? The alternative is running up one vm per customer of one of the many good all-in-one router distros.. Currently each customer is handed off via a dot1q vlan.
Or am I looking at this the wrong way, and should I move all of this onto some decent cisco kit and work on finding a friendly web ui that can manage rules relevant to the client on that device?
Thanks in advance
-dave.
_______________________________________________
AusNOG mailing list
AusNOG at lists.ausnog.net<mailto:AusNOG at lists.ausnog.net>
http://lists.ausnog.net/mailman/listinfo/ausnog
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ausnog.net/pipermail/ausnog/attachments/20130428/71768707/attachment.html>
More information about the AusNOG
mailing list