Site to Site IPsec tunnels with 3rd party vendors | ||||
Description | Versa-110/CSG750/CSG355/CSG365 or 4 core and 8G VM | Versa-120/versa 520/CSG770 or 8 core and 16G VM | Versa 810/VEP-4600-V910 or 8 core and 16G VM | Versa 1000/VEP-4600-V930/CSG1300 or 14 core and 32G VM |
Number of IPsec tunnels | 250 | 1000 | 1000 | 2000 |
Note: Above numbers are for route based IPsec. Above number gets reduced by 50% for policy based VPN with same number of SA.
Recommendation for Virtual machine (VM):
- With the same resources(same CPU class/speed, memory, disk) as a bare-metal installation, the performance of VM headend components is about 25 percent less because of the virtualization.
- On the VM host, you must allocate a dedicated CPU and dedicated memory to the Versa headend VMs. This is called 1:1 provisioning.
- You must pin the CPU to the VM vCPU.
- You must disable hyperthreading on the VM host.
- The preferred NICs are SR-IOV NICs, which provide the best network I/O. A second choice is a VirtIO NIC driver. For VMWare, it is recommended that you use VMXNET3 on all interfaces.