Solved

Cisco 2600 Point-To-Point T1 Line Configuration

Posted on 2004-08-23
2
405 Views
Last Modified: 2010-04-11
Ok, I have my "theoretical T1" (loopback) working between the two routers (this is in preparation for the T1 being installed tomorrow), and when I asked a question regarding network setup, I was told I should place the routers inside my firewall.
First, here is my network setup:

<Building 1>                                                                                                          <Building 2>

       <ISP>---------------------------------------------<Internet>----------------------------------<ISP>
              |                                                                                                                       |
         -----------------------------------------------------                                          ---------------------------------------------
        |Firewall w/ VPN Tunnel to Building 2             |                                        |FireWall w/ VPN Tunnel to Building 1   |
        |6 public IPs, 1 private ip(10.0.0.1), using NAT|                                        |1 public IP, 1 private IP (10.10.0.1,NAT|
         -----------------------------------------------------                                          ---------------------------------------------
              |                                                                                                                       |
       Servers & Clients (10.0.x.x)                                                                          Servers & Clients (10.10.x.x)

At Building 2 we have a VoIP telephone system that integrated with our PBX at Building 1.

Because of the crummy connection via DSL to the 'Net, they do not work. So instead of having bad phones, we went ahead and purchased a point to point T1 connection.

From an earlier question, I found that it would be best to put the T1 behind one firewall, and setup my network as follows:

<Building 1>                                                                                                          <Building 2>

          <ISP>
              |                                                                                                                      
         -----------------------------------------------------                                        
        |Firewall  w/VPN from other location s            |                                        
        |6 public IPs, 1 private ip(10.0.0.1), using NAT|                                      
         -----------------------------------------------------
                             |
          ------------------------------------------                                                       -------------------------------------------
         |2600 with T1 Connection (10.0.0.2)|-------------------<T1>-----------------|2600 with T1 Connection (10.10.0.2)|
          ------------------------------------------                                                       -------------------------------------------
                             |                                                                                                               |
       Servers & Clients (10.0.x.x)                                                                          Servers & Clients (10.10.x.x)

Is this the best way to do this? If so, how do I get everything to talk to each other? I have NO experience with Cisco routers, and have accomplished getting the T1 link to work, and I can route Building 1 router to building 2 router, but it will not go any further. My only other alternative is to go back to the other way I was thinking, which was to put the T1 outside the firewall, then use VPN to connect the two networks together. There also are other remote sites that contact the firewall in building 1 for connectivity. Why couldn't that DSL line work?!?!!? :-D

Thanks for the help everyone, I look forward to your responses.
 - Peter

Ps. I have the config files for my routers, here they are: Building 1 is NDSGP, Building 2 is JoshuaCross.

Current configuration : 842 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname NDSGP
!
boot-start-marker
boot-end-marker
!
enable secret
enable password
!
memory-size iomem 10
no aaa new-model
ip subnet-zero
ip cef
!
!
!
ip audit po max-events 100
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface Ethernet0/0
 ip address 10.0.0.2 255.255.0.0
 half-duplex
!
interface Serial0/0
 ip address 10.20.0.1 255.255.0.0
 encapsulation ppp
 fair-queue
 service-module t1 timeslots 1-24
!
router eigrp 1
 network 10.0.0.0 0.0.255.255
 auto-summary
!
ip default-gateway 10.10.0.2
ip http server
no ip http secure-server
ip classless
!
!
dialer-list 1 protocol ip permit
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
 password
 login
!
!
!
end

--------------------------------------------------------------------------------
Current configuration : 1159 bytes
!
version 12.3
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname JoshuaCross
!
boot-start-marker
boot-end-marker
!
enable secret
enable password
!
memory-size iomem 10
no aaa new-model
ip subnet-zero
ip cef
!
!
ip name-server 10.10.0.101
ip name-server 10.0.0.101
!
ip audit po max-events 100
prompt JoshuaCross>
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface Ethernet0/0
 ip address 10.10.0.2 255.255.0.0
 half-duplex
!
interface Serial0/0
 bandwidth 1500
 ip address 10.20.0.2 255.255.0.0
 encapsulation ppp
 fair-queue
 service-module t1 clock source internal
 service-module t1 timeslots 1-24
!
router eigrp 1
 network 10.10.0.0 0.0.255.255
 network 10.0.0.0
 auto-summary
!
ip default-gateway 10.10.0.1
no ip http server
no ip http secure-server
ip classless
ip route 10.0.0.0 255.255.0.0 10.10.0.1
ip route 10.10.0.0 255.255.0.0 Serial0/0
!
!
dialer-list 1 protocol ip permit
!
!
!
!
gateway
!
!
banner motd ^C Welcome to the Joshua/Cross Router!^C
!
line con 0
 password
 login
line aux 0
line vty 0 4
 password
 login
!
!
!
end
0
Comment
Question by:plewis1250
2 Comments
 
LVL 4

Accepted Solution

by:
syn_ack_fin earned 500 total points
ID: 11874955
add the following eigrp statement to both routers:
network 10.20.0.0 0.0.255.255

On the second router copy the following:
no ip default-gateway 10.10.0.1
add ip default-gateway 10.20.0.1
no ip route 10.0.0.0 255.255.0.0 10.10.0.1
no ip route 10.10.0.0 255.255.0.0 Serial0/0


Also, the firewall should have a static route to the remote network. Something that says:

if trying to get to 10.10.0.0 255.255.0.0 use gateway 10.0.0.2

Good Luck
0
 

Author Comment

by:plewis1250
ID: 11916025
Thanks for your help! I had to modify a few other settings, but the largest problem was the static routes. But I have a clear understanding of how the routing tables work now thanks to you! Once again, thanks!
 - Peter
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question