[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Cisco 2600 Point-To-Point T1 Line Configuration

Posted on 2004-08-23
2
Medium Priority
?
428 Views
Last Modified: 2010-04-11
Ok, I have my "theoretical T1" (loopback) working between the two routers (this is in preparation for the T1 being installed tomorrow), and when I asked a question regarding network setup, I was told I should place the routers inside my firewall.
First, here is my network setup:

<Building 1>                                                                                                          <Building 2>

       <ISP>---------------------------------------------<Internet>----------------------------------<ISP>
              |                                                                                                                       |
         -----------------------------------------------------                                          ---------------------------------------------
        |Firewall w/ VPN Tunnel to Building 2             |                                        |FireWall w/ VPN Tunnel to Building 1   |
        |6 public IPs, 1 private ip(10.0.0.1), using NAT|                                        |1 public IP, 1 private IP (10.10.0.1,NAT|
         -----------------------------------------------------                                          ---------------------------------------------
              |                                                                                                                       |
       Servers & Clients (10.0.x.x)                                                                          Servers & Clients (10.10.x.x)

At Building 2 we have a VoIP telephone system that integrated with our PBX at Building 1.

Because of the crummy connection via DSL to the 'Net, they do not work. So instead of having bad phones, we went ahead and purchased a point to point T1 connection.

From an earlier question, I found that it would be best to put the T1 behind one firewall, and setup my network as follows:

<Building 1>                                                                                                          <Building 2>

          <ISP>
              |                                                                                                                      
         -----------------------------------------------------                                        
        |Firewall  w/VPN from other location s            |                                        
        |6 public IPs, 1 private ip(10.0.0.1), using NAT|                                      
         -----------------------------------------------------
                             |
          ------------------------------------------                                                       -------------------------------------------
         |2600 with T1 Connection (10.0.0.2)|-------------------<T1>-----------------|2600 with T1 Connection (10.10.0.2)|
          ------------------------------------------                                                       -------------------------------------------
                             |                                                                                                               |
       Servers & Clients (10.0.x.x)                                                                          Servers & Clients (10.10.x.x)

Is this the best way to do this? If so, how do I get everything to talk to each other? I have NO experience with Cisco routers, and have accomplished getting the T1 link to work, and I can route Building 1 router to building 2 router, but it will not go any further. My only other alternative is to go back to the other way I was thinking, which was to put the T1 outside the firewall, then use VPN to connect the two networks together. There also are other remote sites that contact the firewall in building 1 for connectivity. Why couldn't that DSL line work?!?!!? :-D

Thanks for the help everyone, I look forward to your responses.
 - Peter

Ps. I have the config files for my routers, here they are: Building 1 is NDSGP, Building 2 is JoshuaCross.

Current configuration : 842 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname NDSGP
!
boot-start-marker
boot-end-marker
!
enable secret
enable password
!
memory-size iomem 10
no aaa new-model
ip subnet-zero
ip cef
!
!
!
ip audit po max-events 100
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface Ethernet0/0
 ip address 10.0.0.2 255.255.0.0
 half-duplex
!
interface Serial0/0
 ip address 10.20.0.1 255.255.0.0
 encapsulation ppp
 fair-queue
 service-module t1 timeslots 1-24
!
router eigrp 1
 network 10.0.0.0 0.0.255.255
 auto-summary
!
ip default-gateway 10.10.0.2
ip http server
no ip http secure-server
ip classless
!
!
dialer-list 1 protocol ip permit
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
 password
 login
!
!
!
end

--------------------------------------------------------------------------------
Current configuration : 1159 bytes
!
version 12.3
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname JoshuaCross
!
boot-start-marker
boot-end-marker
!
enable secret
enable password
!
memory-size iomem 10
no aaa new-model
ip subnet-zero
ip cef
!
!
ip name-server 10.10.0.101
ip name-server 10.0.0.101
!
ip audit po max-events 100
prompt JoshuaCross>
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface Ethernet0/0
 ip address 10.10.0.2 255.255.0.0
 half-duplex
!
interface Serial0/0
 bandwidth 1500
 ip address 10.20.0.2 255.255.0.0
 encapsulation ppp
 fair-queue
 service-module t1 clock source internal
 service-module t1 timeslots 1-24
!
router eigrp 1
 network 10.10.0.0 0.0.255.255
 network 10.0.0.0
 auto-summary
!
ip default-gateway 10.10.0.1
no ip http server
no ip http secure-server
ip classless
ip route 10.0.0.0 255.255.0.0 10.10.0.1
ip route 10.10.0.0 255.255.0.0 Serial0/0
!
!
dialer-list 1 protocol ip permit
!
!
!
!
gateway
!
!
banner motd ^C Welcome to the Joshua/Cross Router!^C
!
line con 0
 password
 login
line aux 0
line vty 0 4
 password
 login
!
!
!
end
0
Comment
Question by:plewis1250
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 4

Accepted Solution

by:
syn_ack_fin earned 2000 total points
ID: 11874955
add the following eigrp statement to both routers:
network 10.20.0.0 0.0.255.255

On the second router copy the following:
no ip default-gateway 10.10.0.1
add ip default-gateway 10.20.0.1
no ip route 10.0.0.0 255.255.0.0 10.10.0.1
no ip route 10.10.0.0 255.255.0.0 Serial0/0


Also, the firewall should have a static route to the remote network. Something that says:

if trying to get to 10.10.0.0 255.255.0.0 use gateway 10.0.0.2

Good Luck
0
 

Author Comment

by:plewis1250
ID: 11916025
Thanks for your help! I had to modify a few other settings, but the largest problem was the static routes. But I have a clear understanding of how the routing tables work now thanks to you! Once again, thanks!
 - Peter
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question