Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


Solarwinds Orion

Posted on 2009-05-14
Medium Priority
Last Modified: 2012-06-27
All, I am considering using Solarwinds Orion to set up a small business monitoring service. In trying to come up with a workable model I know I have several things to consider. I am attempting to model this using the Internet as my transport, probably via a VPN tunnel. The most pressing issue I have is that if some of these remote sites are using the same subnet IP's there will be a conflict in the monitoring per customer. So my question(s): Obviously looking for a least cost solution what is best VPN method and how do I resolve the same IP subnet dilemma?
Thanks much Robb
Question by:Robbt
  • 2
  • 2
LVL 33

Expert Comment

ID: 24389998
Mapping VPN endpoints that have overlapping subnets is perfectly do-able with the right setup.  

Alot of the detail work will depend on the exact VPN endpoint hardware you are using.  

It basically involves Nating the traffic at each endpoint before it is sent to the VPN tunnel.  

Have a look at this example:

That should give you a basic idea of what to expect.  

Now to get this implemented, you woul dneed to know what hardware you are going to be running.  

Author Comment

ID: 24391802
Thanks for the information Mike.

I am not an expert on this but am surely learning. Per the link you supplied it appears that this solution would require Policy Based NAT. I must assume that since this will be a service for remote customers (unknown) there will be many flavors of devices I can expect to run in to that may be on differing platforms and may or may not support Policy Based NAT. And that in itself can be a challenge let alone resolving my original question.

While my "ultimate" goal is to creat a $0 dollar setup at remote customer sites ( and no hardware installation) that may not be feasible for the above reasons. I am wondering if i might need to consider a hardware device like a VPN-1 Edge appliancefrom Check Point at customer sites.

Might you have any other suggestions?



LVL 33

Accepted Solution

MikeKane earned 1000 total points
ID: 24396145
I can tell you what I've seen in my experience dealing with remote monitoring companies.    There was a minimum requirement  on the customer side with regards to a VPN endpoint.    "The customer must have one of these supported routers...." otherwise the monitoring company would have been happy to sell me the device and service time to set it up.   This would be understandable since it would be unfeasible to believe that a single startup host could support every possible combination of devices.      Instead, my advice would be to concentrate on the manufacturer with the largest market share in the demographic you are targeting.  Cisco and checkpoint are probably safe bets, but dont overlook sonicwall or juniper.      It would be easy enough to contact pre-sales tech support for whatever equipment you are looking at to verify what it can and can't work with in regards to this setup.  

Cisco ASA certainly establish site 2 site vpns with pretty much any other endpoint.   Plus, you should be able to do a Nat on your side even if the client doesn't have the capability.    

You could always request a single host at the client site running a collector for Solarwinds that connects via client, or ask for a single ip statically mapped to the host...  instead of a site to site vpn setup....    

The point is be flexible when you are starting up.  

Hope that helps.  

Author Closing Comment

ID: 31581706

My apologies for not communicating sooner. I did take some time to discuss (as advised) various options with a few vendors and took in to consideration that I may have to "request" an interested customer to provide NAT'ng on their end as part of any technical arrangement. Accepting that there just may be some clients that cannot provide the right methodologies for a feasable solution to the problem. I do think that using a "Major" vendor product like CISCO and their ASA devices provides the best possibility of accomplishing what I am looking for. Thank you for your insight as this extended beyond the scope of a "Technical" solution and into the world of a business requirement.


Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
This article will show you step-by-step instructions to build your own NTP CentOS server.  The network diagram shows the best practice to setup the NTP server farm for redundancy.  This article also serves as your NTP server documentation.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Suggested Courses

575 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question