Solved

Cisco 2600 Point-To-Point T1 Line Configuration

Posted on 2004-08-23
2
399 Views
Last Modified: 2010-04-11
Ok, I have my "theoretical T1" (loopback) working between the two routers (this is in preparation for the T1 being installed tomorrow), and when I asked a question regarding network setup, I was told I should place the routers inside my firewall.
First, here is my network setup:

<Building 1>                                                                                                          <Building 2>

       <ISP>---------------------------------------------<Internet>----------------------------------<ISP>
              |                                                                                                                       |
         -----------------------------------------------------                                          ---------------------------------------------
        |Firewall w/ VPN Tunnel to Building 2             |                                        |FireWall w/ VPN Tunnel to Building 1   |
        |6 public IPs, 1 private ip(10.0.0.1), using NAT|                                        |1 public IP, 1 private IP (10.10.0.1,NAT|
         -----------------------------------------------------                                          ---------------------------------------------
              |                                                                                                                       |
       Servers & Clients (10.0.x.x)                                                                          Servers & Clients (10.10.x.x)

At Building 2 we have a VoIP telephone system that integrated with our PBX at Building 1.

Because of the crummy connection via DSL to the 'Net, they do not work. So instead of having bad phones, we went ahead and purchased a point to point T1 connection.

From an earlier question, I found that it would be best to put the T1 behind one firewall, and setup my network as follows:

<Building 1>                                                                                                          <Building 2>

          <ISP>
              |                                                                                                                      
         -----------------------------------------------------                                        
        |Firewall  w/VPN from other location s            |                                        
        |6 public IPs, 1 private ip(10.0.0.1), using NAT|                                      
         -----------------------------------------------------
                             |
          ------------------------------------------                                                       -------------------------------------------
         |2600 with T1 Connection (10.0.0.2)|-------------------<T1>-----------------|2600 with T1 Connection (10.10.0.2)|
          ------------------------------------------                                                       -------------------------------------------
                             |                                                                                                               |
       Servers & Clients (10.0.x.x)                                                                          Servers & Clients (10.10.x.x)

Is this the best way to do this? If so, how do I get everything to talk to each other? I have NO experience with Cisco routers, and have accomplished getting the T1 link to work, and I can route Building 1 router to building 2 router, but it will not go any further. My only other alternative is to go back to the other way I was thinking, which was to put the T1 outside the firewall, then use VPN to connect the two networks together. There also are other remote sites that contact the firewall in building 1 for connectivity. Why couldn't that DSL line work?!?!!? :-D

Thanks for the help everyone, I look forward to your responses.
 - Peter

Ps. I have the config files for my routers, here they are: Building 1 is NDSGP, Building 2 is JoshuaCross.

Current configuration : 842 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname NDSGP
!
boot-start-marker
boot-end-marker
!
enable secret
enable password
!
memory-size iomem 10
no aaa new-model
ip subnet-zero
ip cef
!
!
!
ip audit po max-events 100
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface Ethernet0/0
 ip address 10.0.0.2 255.255.0.0
 half-duplex
!
interface Serial0/0
 ip address 10.20.0.1 255.255.0.0
 encapsulation ppp
 fair-queue
 service-module t1 timeslots 1-24
!
router eigrp 1
 network 10.0.0.0 0.0.255.255
 auto-summary
!
ip default-gateway 10.10.0.2
ip http server
no ip http secure-server
ip classless
!
!
dialer-list 1 protocol ip permit
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
 password
 login
!
!
!
end

--------------------------------------------------------------------------------
Current configuration : 1159 bytes
!
version 12.3
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname JoshuaCross
!
boot-start-marker
boot-end-marker
!
enable secret
enable password
!
memory-size iomem 10
no aaa new-model
ip subnet-zero
ip cef
!
!
ip name-server 10.10.0.101
ip name-server 10.0.0.101
!
ip audit po max-events 100
prompt JoshuaCross>
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface Ethernet0/0
 ip address 10.10.0.2 255.255.0.0
 half-duplex
!
interface Serial0/0
 bandwidth 1500
 ip address 10.20.0.2 255.255.0.0
 encapsulation ppp
 fair-queue
 service-module t1 clock source internal
 service-module t1 timeslots 1-24
!
router eigrp 1
 network 10.10.0.0 0.0.255.255
 network 10.0.0.0
 auto-summary
!
ip default-gateway 10.10.0.1
no ip http server
no ip http secure-server
ip classless
ip route 10.0.0.0 255.255.0.0 10.10.0.1
ip route 10.10.0.0 255.255.0.0 Serial0/0
!
!
dialer-list 1 protocol ip permit
!
!
!
!
gateway
!
!
banner motd ^C Welcome to the Joshua/Cross Router!^C
!
line con 0
 password
 login
line aux 0
line vty 0 4
 password
 login
!
!
!
end
0
Comment
Question by:plewis1250
2 Comments
 
LVL 4

Accepted Solution

by:
syn_ack_fin earned 500 total points
ID: 11874955
add the following eigrp statement to both routers:
network 10.20.0.0 0.0.255.255

On the second router copy the following:
no ip default-gateway 10.10.0.1
add ip default-gateway 10.20.0.1
no ip route 10.0.0.0 255.255.0.0 10.10.0.1
no ip route 10.10.0.0 255.255.0.0 Serial0/0


Also, the firewall should have a static route to the remote network. Something that says:

if trying to get to 10.10.0.0 255.255.0.0 use gateway 10.0.0.2

Good Luck
0
 

Author Comment

by:plewis1250
ID: 11916025
Thanks for your help! I had to modify a few other settings, but the largest problem was the static routes. But I have a clear understanding of how the routing tables work now thanks to you! Once again, thanks!
 - Peter
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
Learn how to PXE Boot both BIOS & UEFI machines with DHCP Policies and Custom Vendor Classes
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question