Solved

IPSec VPN - Bridge setup

Posted on 2010-08-26
3
915 Views
Last Modified: 2013-11-16
Hi,

I have to setup an IPSec VPN between to sites with juniper firewalls and we would like to communicate the two sited through the same network, I think this is called "Bridge setup".

We have the network 10.100.2.0/24 and the other site want to use the same network... Is it possible?, How should we configure this environment?.

Thanks in advanced.
/regards.
0
Comment
Question by:ecemibm
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 4

Accepted Solution

by:
ythevenot earned 400 total points
ID: 33529693
0
 
LVL 70

Assisted Solution

by:Qlemo
Qlemo earned 100 total points
ID: 33529705
No - not that easy, at least. Juniper does not support ethernet bridging via an IPSec tunnel. You need to apply routing, and that means that you can't use the same addresses on both sides. The Juniper devices need to know where to go to for each address referenced, and the local stations need to differ between both networks.
My recommendation is to use the lower half at one site and the upper at the other, making a /25 network each. The core network address remains, but it is always straightforward at which side an address is located.

Another workaround is to use 1:1 NAT on both sides. That is, translate site A addresses to 10.100.3.0/24 on site B, and site B addresses on site A to 10.100.4.0/24. However, that confuses services working with IP addresses, like DNS - you would need to manually set that up on each site (for the other site). I do not recommend this.
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 33529731
The PDF above shows the second method I mentioned.
0

Featured Post

Will You Be GDPR Compliant by 5/28/2018?

GDPR? That's a regulation for the European Union. But, if you collect data from customers or employees within the EU, then you need to know about GDPR and make sure your organization is compliant by May 2018. Check out our preparation checklist to make sure you're on track today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Need assistance with Windows Firewall rules 6 120
SSIS with VPN COnnection 2 142
IP Address white listing in Windows Firewall 5 61
pfsense upgrade from 2.2.6 to 2.3.3 28 86
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question