It is accomplished using many vrfs on (2) Cisco 1841s. For those less technical, VRFs are essentially private routing tables similar to a VPN. When a packet destined to 18.104.22.168 (AKA obiwan.scrye.net) hits my main gateway, I forward it onto the first VRF on the “ASIDE” router on 22.214.171.124. That router then has a specific route for 126.96.36.199 to 188.8.131.52, which resides on a different VRF on the “BSIDE” router. It then has a similar set up which points it at 184.108.40.206 which lives in another VPN on “ASIDE” router. All packets are returned using a default route pointing at the global routing table. This was by design so the packets TTL expiration did not have to return fully through the VRF Maze.
« Older Submitted for your enjoyment: The misadventures of... | Since March 21, 1994, when the... Newer »
This thread has been archived and is closed to new comments
Buy a Shirt