Solved

MPLS Best Practices.  Is it best practice to have an MPLS line going directly to the LAN switch or through a firewall first?

Posted on 2008-10-30
1
891 Views
Last Modified: 2008-11-10
It seems to me you can control traffic using the MPLS router.  We have an MPLS line that connects offices A (us), B and C.  It hits a Sonic firewall on A (us) before it gets into our LAN.

Office "B" is trying to hit our local LAN and it works fine.  

Office "C" wants to hit our LAN and then use our internet gateway to get out to the net.  This doesn't seem to be working when they try to reach the net thru us though.  Is there a better way to accomplish this?



                          SONICWALL           SONIC WALL  
                                   |                              |
Office B-----MPLS------>Office A (us)---------OUR Internet---(office C is trying to go out thru us)
                                               | SONIC WALL
                                            mpls
                                          Office C    



0
Comment
Question by:Sp0cky
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 22842222
Myself, I would personally have the private MPLS come into the switch instead of the Firewall as these are internal sites (unless you want to restrict traffic obviously).  This would also make your Sonicwall policy more simple and take care of the "hairpin" issue you are experiencing with traffic coming into the Firewall outside and going back out the outside interface to the Internet.
0

Featured Post

Don't Miss ATEN at InfoComm 2017!

Visit booth #2167 to see the  new ATEN VM3200 32 x 32 Modular Matrix Switch. Other highlights include the VE8950 4K HDMI Over IP Extender, VS1912 12-Port DP Video Wall Media Player  and VK2100 ATEN Control System. Register now with Free Pass Code ATEN288!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
As companies replace their old PBX phone systems with Unified IP Communications, many are finding out that legacy applications such as fax do not work well with VoIP. Fortunately, Cloud Faxing provides a cost-effective alternative that works over an…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Suggested Courses

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question