7-22
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 7 Configuring Line Interfaces
Managed VPNs
Managed VPNs
•
Private IP Addresses, page 7-22
•
•
Limitations for VPN mode, page 7-22
A managed VPN is a named entity, introduced similarly to the same way that a subscriber is introduced,
and containing VPN mappings.
A managed VPN contains a single VLAN mapping. A VPN-based subscriber contains a set of mappings
of the form: IP@VpnName, where IP can be either a single IP address or a range of addresses.
Managed VPN entities can be configured only via the SM. The Cisco SCE platform CLI can be used to
view VPN-related information, but not to configure the VPNs.
Private IP Addresses
Private IP addresses are supported only in the following mode, as this mode provides information
regarding the higher-level entity (VLAN or VPN) to which the IP addresses of the flow belong:
•
VLAN symmetric classify
Capacity
The system supports:
•
2048 VPNs
•
80,000 IP mappings over VPNs
Limitations for VPN mode
Mutually exclusive system modes
When the system is working in VPN mode, the following modes are not supported:
•
DDoS
•
Value Added Services (VAS) mode
Subscriber-related limitations
•
The SM must be configured to operate in Push mode.
•
Introduced subscriber aging is not supported when using VPN-based subscribers
TCP-related requirements
•
Number of Upstream TCP Flows – There must be enough TCP flows opening from the subscriber
side on each PE-PE route in each period of time. The higher the rate of TCP flows from the
subscriber side, the higher the accuracy of the mechanism can be.
VPN configuration requirements
•
In VLAN-based VPNs (VLAN symmetric classify mode), a subscriber may have IP mappings over
more than one VPN, but only if the IP mappings are the full range of the VPN (0.0.0.0/0). (This
option is provided for backwards compatibility, supporting legacy multi-VLAN subscribers.)