Public IP Hand-off
Hello,
I need to provide Managed Wan Connectivity + Wireless Failover to a customer who is managing their own network, their Edge device is a Meraki MX firewall. They need Public static IP addresses on the MX.
I use ISPs to provide the last mile connectivity which, in most cases is Off-Net Braodband Cable or FTTP (this is not dedicated fibre).
I would like to use FG40Fs to terminate the WAN connectivy (so I can manage it ), then hand-off the Public IP to the MX over a switchport. Then setup GRE tunnels back to my core network so I can route and advertise the Public IPs. One Primary tunnel and one Failover tunnel.
I've been told that this has many disadvantages: A) the GRE tunnel overhead, B) the Cable (DOCSIS) variable latency & potential packet loss, and C) and tunneling already tunneled and encrypted traffic. I've also been told that, despite the specs in its datasheet, a FG40F wil not be able to deliver more than 100-200Mbps throughput because the GRE tunnels and DOCSIS nature.
Could you please provide some advise on how to best implement this (IP-VPN or SD-WAN solutions are not posible alternatives)? Can this be done with a FG? How should I size the FG? What will be the setup/Configuration to be use? Any advise will be much appreacited.
