Solved

Cisco 2600 Point-To-Point T1 Line Configuration

Posted on 2004-08-23
2
383 Views
Last Modified: 2010-04-11
Ok, I have my "theoretical T1" (loopback) working between the two routers (this is in preparation for the T1 being installed tomorrow), and when I asked a question regarding network setup, I was told I should place the routers inside my firewall.
First, here is my network setup:

<Building 1>                                                                                                          <Building 2>

       <ISP>---------------------------------------------<Internet>----------------------------------<ISP>
              |                                                                                                                       |
         -----------------------------------------------------                                          ---------------------------------------------
        |Firewall w/ VPN Tunnel to Building 2             |                                        |FireWall w/ VPN Tunnel to Building 1   |
        |6 public IPs, 1 private ip(10.0.0.1), using NAT|                                        |1 public IP, 1 private IP (10.10.0.1,NAT|
         -----------------------------------------------------                                          ---------------------------------------------
              |                                                                                                                       |
       Servers & Clients (10.0.x.x)                                                                          Servers & Clients (10.10.x.x)

At Building 2 we have a VoIP telephone system that integrated with our PBX at Building 1.

Because of the crummy connection via DSL to the 'Net, they do not work. So instead of having bad phones, we went ahead and purchased a point to point T1 connection.

From an earlier question, I found that it would be best to put the T1 behind one firewall, and setup my network as follows:

<Building 1>                                                                                                          <Building 2>

          <ISP>
              |                                                                                                                      
         -----------------------------------------------------                                        
        |Firewall  w/VPN from other location s            |                                        
        |6 public IPs, 1 private ip(10.0.0.1), using NAT|                                      
         -----------------------------------------------------
                             |
          ------------------------------------------                                                       -------------------------------------------
         |2600 with T1 Connection (10.0.0.2)|-------------------<T1>-----------------|2600 with T1 Connection (10.10.0.2)|
          ------------------------------------------                                                       -------------------------------------------
                             |                                                                                                               |
       Servers & Clients (10.0.x.x)                                                                          Servers & Clients (10.10.x.x)

Is this the best way to do this? If so, how do I get everything to talk to each other? I have NO experience with Cisco routers, and have accomplished getting the T1 link to work, and I can route Building 1 router to building 2 router, but it will not go any further. My only other alternative is to go back to the other way I was thinking, which was to put the T1 outside the firewall, then use VPN to connect the two networks together. There also are other remote sites that contact the firewall in building 1 for connectivity. Why couldn't that DSL line work?!?!!? :-D

Thanks for the help everyone, I look forward to your responses.
 - Peter

Ps. I have the config files for my routers, here they are: Building 1 is NDSGP, Building 2 is JoshuaCross.

Current configuration : 842 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname NDSGP
!
boot-start-marker
boot-end-marker
!
enable secret
enable password
!
memory-size iomem 10
no aaa new-model
ip subnet-zero
ip cef
!
!
!
ip audit po max-events 100
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface Ethernet0/0
 ip address 10.0.0.2 255.255.0.0
 half-duplex
!
interface Serial0/0
 ip address 10.20.0.1 255.255.0.0
 encapsulation ppp
 fair-queue
 service-module t1 timeslots 1-24
!
router eigrp 1
 network 10.0.0.0 0.0.255.255
 auto-summary
!
ip default-gateway 10.10.0.2
ip http server
no ip http secure-server
ip classless
!
!
dialer-list 1 protocol ip permit
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
 password
 login
!
!
!
end

--------------------------------------------------------------------------------
Current configuration : 1159 bytes
!
version 12.3
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname JoshuaCross
!
boot-start-marker
boot-end-marker
!
enable secret
enable password
!
memory-size iomem 10
no aaa new-model
ip subnet-zero
ip cef
!
!
ip name-server 10.10.0.101
ip name-server 10.0.0.101
!
ip audit po max-events 100
prompt JoshuaCross>
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface Ethernet0/0
 ip address 10.10.0.2 255.255.0.0
 half-duplex
!
interface Serial0/0
 bandwidth 1500
 ip address 10.20.0.2 255.255.0.0
 encapsulation ppp
 fair-queue
 service-module t1 clock source internal
 service-module t1 timeslots 1-24
!
router eigrp 1
 network 10.10.0.0 0.0.255.255
 network 10.0.0.0
 auto-summary
!
ip default-gateway 10.10.0.1
no ip http server
no ip http secure-server
ip classless
ip route 10.0.0.0 255.255.0.0 10.10.0.1
ip route 10.10.0.0 255.255.0.0 Serial0/0
!
!
dialer-list 1 protocol ip permit
!
!
!
!
gateway
!
!
banner motd ^C Welcome to the Joshua/Cross Router!^C
!
line con 0
 password
 login
line aux 0
line vty 0 4
 password
 login
!
!
!
end
0
Comment
Question by:plewis1250
2 Comments
 
LVL 4

Accepted Solution

by:
syn_ack_fin earned 500 total points
Comment Utility
add the following eigrp statement to both routers:
network 10.20.0.0 0.0.255.255

On the second router copy the following:
no ip default-gateway 10.10.0.1
add ip default-gateway 10.20.0.1
no ip route 10.0.0.0 255.255.0.0 10.10.0.1
no ip route 10.10.0.0 255.255.0.0 Serial0/0


Also, the firewall should have a static route to the remote network. Something that says:

if trying to get to 10.10.0.0 255.255.0.0 use gateway 10.0.0.2

Good Luck
0
 

Author Comment

by:plewis1250
Comment Utility
Thanks for your help! I had to modify a few other settings, but the largest problem was the static routes. But I have a clear understanding of how the routing tables work now thanks to you! Once again, thanks!
 - Peter
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Network Connection 5 31
Login to my old Sonicwall TZ210 5 24
DHCP on ASA 3 20
W 10 Workstation can't join Win 2012 domain 12 23
#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now