Solved

IPSec VPN - Bridge setup

Posted on 2010-08-26
3
908 Views
Last Modified: 2013-11-16
Hi,

I have to setup an IPSec VPN between to sites with juniper firewalls and we would like to communicate the two sited through the same network, I think this is called "Bridge setup".

We have the network 10.100.2.0/24 and the other site want to use the same network... Is it possible?, How should we configure this environment?.

Thanks in advanced.
/regards.
0
Comment
Question by:ecemibm
  • 2
3 Comments
 
LVL 4

Accepted Solution

by:
ythevenot earned 400 total points
Comment Utility
0
 
LVL 68

Assisted Solution

by:Qlemo
Qlemo earned 100 total points
Comment Utility
No - not that easy, at least. Juniper does not support ethernet bridging via an IPSec tunnel. You need to apply routing, and that means that you can't use the same addresses on both sides. The Juniper devices need to know where to go to for each address referenced, and the local stations need to differ between both networks.
My recommendation is to use the lower half at one site and the upper at the other, making a /25 network each. The core network address remains, but it is always straightforward at which side an address is located.

Another workaround is to use 1:1 NAT on both sides. That is, translate site A addresses to 10.100.3.0/24 on site B, and site B addresses on site A to 10.100.4.0/24. However, that confuses services working with IP addresses, like DNS - you would need to manually set that up on each site (for the other site). I do not recommend this.
0
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
The PDF above shows the second method I mentioned.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Overview Often, we set up VPN appliances where the connected clients are on a separate subnet and the company will have alternate internet connections and do not use this particular device as the gateway for certain servers or clients. In this case…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now