Solved

Can't Route Traffice Between 2 Branch Offices Using Netscreen Routers

Posted on 2008-10-31
7
700 Views
Last Modified: 2012-05-05
I have inherited a network consisting of a main operation office and 2 branch offices. For conectivity, the main office uses a Juniper Networks Netscreen NS-25 and the branch offices use  Netscreen NS5XP & NS5GT. By looking at the existing policies I can see that the main office is connected to each branch office via VPN tunnel. At the main office I can ping each branch office and vice versa, however while at branch office 1, I cannot ping branch office 2.

I'm sure that what I am trying to do is possible, I just am too unfamiliar with JUNOS. Essentially I would like to do this: Route traffic between 2 branch offices using the main office as a go between. Consider this diagram of the current network:

Branch 1 <----VPN----> Main                              Branch 2 <----VPN----> Main
(dedicated IP on both public sides)                   (Dynamic IP at Branch 2)

I would like to accomplish the following:

Branch1 <---- Main ----> Branch2

Any suggestion would greatly be appreciated.
0
Comment
Question by:ezg5016
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 32

Expert Comment

by:harbor235
ID: 22856802


What are you pinging at branch office 2? Hopefully it is something inside and not the VPN termination point?


harbor235 ;}
0
 

Author Comment

by:ezg5016
ID: 22857489
From Branch office 1 segment (192.168.253.1/24) I can ping main office segment (10.1.1.1/24) and vice versa. Same holds true for Branch office 2. Server farm lives in the main office segment so both branches can ping within.

We installed a data collection device within the branch office 2 segment (10.3.1.1/24) but the data monitoring software is installed at the Branch office 1 segment.

I hope this helps.
0
 
LVL 5

Accepted Solution

by:
thechaosrealm earned 168 total points
ID: 22924558
Here's how the NetScreens work. To set up a secure network between two sites, you must configure a VPN tunnel. If you have multiple sites, you must configure a VPN tunnel between every two sites you want to see each other.

Branch 1 <----> Main <----> Branch 2  

What this is showing is that Branch 1 and Main can communicate both directions and Branch 2 and Main can communicate both directions. If you want Branch 1 and Branch 2 to communicate, you must create an additional tunnel.

Branch 1 <----> Main <----> Branch 2
Branch 1 <----> Branch 2

The steps for doing this are quite similar as they would be for setting up Branch 1 to main, but let me know if you need help with that portion.


0
Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

 
LVL 2

Assisted Solution

by:DeanGoldhill
DeanGoldhill earned 166 total points
ID: 23172439
I would say the comment my thechaosrealm: is the best approch.

However, this would not use the main office as a 'go through'.
But I dont think using the main office as a 'go through' is a good idea, traffic is will much slower and I dont see any benifits!

But if you really want to do it like that,  you should be able to just create a route on each client (routing traffic for the other client to the main office) and a policy on the main office that says traffic going from client 1 must use the VPN tunnel to client 2.

Any jsut by the way, Netscreens and SSG's run on ScreenOS not JUNOS (just in case you try load wrong software).

Good Luck
Cheers
0
 

Author Comment

by:ezg5016
ID: 23176353
Thank you all. I have been away on special project and am revisiting this issue later this afternoon. I will keep you posted
0
 
LVL 70

Assisted Solution

by:Qlemo
Qlemo earned 166 total points
ID: 23251546
In Concepts&Examples, Volume 5 VPN, there is a configuration example for "Hub-and-Spoke" VPNs. Those are one-main-office-to-many-branches VPN tunnels for communicating in all directions. However, the traffic volume (and therefore performance) is affected. It is appropriate if one of the following is true
  • the branches are that many that a full mesh configuration would not be manageable
  • all traffic has to pass head office, for scanning or logging reasons or whatsoever.
  • the branch office devices are not capable of servicing enough tunnels.
  • inter-branch traffic is not that much and would not justify the configuration overhead for each branch.
If there are only up to 5 sites, I would prefer to use a full mesh configuration - each branch can connect to each other directly.
0

Featured Post

Save the day with this special offer from ATEN!

Save 30% on the CV211 using promo code EXPERTS30 now through April 30th. The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question