<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1705902170274878&amp;ev=PageView&amp;noscript=1">
Skip to content
  • There are no suggestions because the search field is empty.

Network Integration & Mergers and Acquisitions

After a merger or acquisition, two networks must talk quickly but safely. A single control point on the managed edge interconnects the two, enforces a security boundary between them, and resolves overlapping addressing with translation – without a lengthy renumbering project.

When to use it

Use this pattern when two previously separate organisations – or two business units – need to interconnect at pace, and you cannot wait for a full network-integration programme. It gives day-one connectivity with a controlled boundary, buying time for the deeper integration work.

How it works

Both networks attach to a single control point on the IZO™+ Multi Cloud Connect managed edge over private, dedicated connections. A virtual router-firewall on the edge routes between them and enforces a policy boundary, so the two networks are joined but not blindly trusted – you decide exactly which flows cross.

The classic obstacle after a merger is overlapping address space: both organisations independently used the same private ranges. Address translation at the edge lets the two sides reach each other through translated addresses without either renumbering first. Where encryption is required between the networks, IPsec is applied at the network layer on the edge. As integration matures, the same control point can host segmentation policy and distribute into regional control points where regulation or scale requires.

This is deliberately a single control point at day one; because it carries a security-enforcing, often stateful role, the production form uses the active-standby cluster from the High Availability & Redundancy Models page.

Example

A group acquires a competitor and needs shared finance and identity services reachable across both networks within weeks. Both use overlapping private address ranges. Each network attaches privately to a single control point on the managed edge; a virtual router-firewall routes between them, address translation resolves the overlap, and policy allows only the finance and identity flows across the boundary. The businesses interoperate on day one while a longer renumbering and integration programme proceeds behind the scenes.

MCC Visual Reference Architecture & Use Cases-13.12 Network Integration & M&A.drawio-1

IZO™+ Multi Cloud Connect components in this architecture

M&A interconnect is typically a Direct build with several on-ramps and landings joined in a hub topology (Full Mesh / Hub & Spoke):

IZO™+ Multi Cloud Connect Direct (private MPLS underlay):
  • Fabric Port (several) – one per network being interconnected; VPN Topology set to Full Mesh or Hub & Spoke.

  • Virtual Cloud Connection (several) – where either network extends into a cloud.

IZO™+ Multi Cloud Connect Flex (internet underlay with an in-path VNF):
  • Fabric Port (several), Edge Connect, VNF – Router / Firewall, Device Interconnection – where the boundary needs an in-path router-firewall (for NAT and policy).

  • Virtual Cloud Connection – as required.

From the IZO™+ Multi Cloud Connect side, this architecture uses multiple Fabric Ports and Virtual Cloud Connections in a hub topology (add a router/firewall VNF on Flex for the boundary); the Tata Communications-billed parts run to the Virtual Cloud Connections, while any cloud port/attachment and egress sit on your cloud bill.

Considerations

  • Topology - Use the Fabric Port VPN Topology (Full Mesh or Hub & Spoke) to interconnect the networks; a single control point enforces the boundary.

  • Overlapping addressing - The classic M&A obstacle – resolve overlapping private ranges with NAT at the edge (a Flex router/firewall VNF) rather than renumbering first.

  • Enforced boundary - Join the networks but decide exactly which flows cross; apply IPsec at the network layer where encryption between networks is required.

  • Day-one vs mature - Start with a single control point for speed; as integration matures, distribute policy into regional control points where regulation or scale requires.

  • Model - Direct covers plain interconnect; move to Flex where an in-path router-firewall (NAT, policy, encryption) is needed at the boundary.

What’s on the cloud side

Where either network extends into a cloud, that cloud connection is created in the cloud provider’s console. This page covers how the two networks are interconnected and bounded on the Tata Communications side; for the cloud-side connection request and routing, see the relevant per-cloud section.

Related pages