Solved

How to configure network to route traffic to sub-net via one router and everything else on another

Posted on 2009-03-30
6
209 Views
Last Modified: 2013-12-14
Hi,
I've got a network with one main router that's handling Internet access/email/Lan-2-Lan VPNS.

To get better performance I've bought another router so I can transfer the LAN-2-LAN VPN to it.

How can I set the main network up so it routes traffice to the remote site though the second router whilst all other traffic goes though the main router?

I'm using hardware router based  VPNs between the remote site and second router.  The netowrk is a SBS 2003 network.

Thanks!
0
Comment
Question by:jmsjms
  • 3
  • 2
6 Comments
 
LVL 9

Expert Comment

by:hmare
Comment Utility
You will need to create a static route on the main router telling it that all traffic for x.x.x.x (the remote site) uses the second router as its gateway. You will also need some kind of rule allowing access from the wan to the second router, similar to what you would need for a web server.
0
 
LVL 14

Accepted Solution

by:
Roachy1979 earned 500 total points
Comment Utility
Easy way is to set a route in a login script for the remote lan on the workstations.  This avoids traffic getting passed from one router to the other.  If your remote lan has the address range of 192.168.10.0/24 for example and the router for the VPN was 192.168.1.254, your route statement would be

route add 192.168.10.0 mask 255.255.255.0 192.168.1.254

you could make this a persistent route (ie only have to add it once on each machine) with the -p switch on the end, so:

route add 192.168.10.0 mask 255.255.255.0 192.168.1.254 -p

The default gateway for the LAN would remain the same (ie the gateway for the internet connection).

Just add the above to a login script and it will become active when users log in.
0
 

Author Comment

by:jmsjms
Comment Utility
Hi Roachy

I use a VBS loginscript.  Will this work in VBS?  If I have it in their login script with a -p will it just put it in once or will it continue to add it?

Cheers
John
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 
LVL 14

Expert Comment

by:Roachy1979
Comment Utility
If the rule exists it will overwrite the existing rule.....so it should be fine.

Not sure about VBS.  I'm sure you could call a separate batch file from within a VBS login script though...just create a .bat file in the Netlogon folder and place a separate call to run that file....
0
 

Author Comment

by:jmsjms
Comment Utility
I've not yet put it in a script but have used it on a test PC and server.  Works fine on XP and SBS2003 but when I tried it on a W2003 R2 server it didnt like the -p.  Had a look at the /? and it's not listed as an option. Weird eh?

Anyway thanks very much!

John
0
 

Author Closing Comment

by:jmsjms
Comment Utility
Thanks!
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now