Solved

Point to Point Connection with remote site.

Posted on 2010-09-01
3
446 Views
Last Modified: 2012-05-10
Hello Experts:

I have a remote site that is using a DSL line and we here at the corporate office have a 3 meg t-1 line.  I need to funnel all the internet traffic from the remote site into the corporate site so they can be monitored while using the internet.  What do I need (hardware)  to set up a point-to-point connection so that their traffic is routed to us?  For the corporate office, I am looking to replace my SG-5 juniper router with a Palo Alto Firewall.

Thanks
0
Comment
Question by:huntersp3
3 Comments
 
LVL 22

Assisted Solution

by:Matt V
Matt V earned 50 total points
ID: 33580971
You just need a small branch office router at the other end and setup an IPSec VPN tunnel back to home office.  Make the branch router use the main office as it's default route.
0
 
LVL 63

Assisted Solution

by:SysExpert
SysExpert earned 50 total points
ID: 33580984
Well your Juniper could handle this by adding a small netscreen ( NS 5 GT 20x or similar ) at the remote with a VPN tunnel to the office for all Internet traffic.

May also work with any router that can handle a VPN tunnel ( most can )

I hope this helps !
0
 
LVL 3

Accepted Solution

by:
agaskill707 earned 400 total points
ID: 33581093
Any firewall that can do IPSec should do fine.  You can set up an IPSec tunnel where the far end of the tunnel (as the remote side sees it, to the corporate side it would be the near end) is the default network (0.0.0.0/0), which will make all internet traffic come through the IPSec tunnel to the corporate office and then go out the connection there.  Different firewalls might have their own nomenclature for such a tunnel configuration, but fundamentally that's what it is.  Two things to be aware of: 1) Internet access from the remote office will be using double the bandwidth at the corporate office, once to come in from the internet and once to go out to the remote site.  Of course T1s are full duplex, so they can potentially download at 3Mbit, it's just that it will be saturating both inbound and outbound bandwidth at corporate.  2) Some firewalls need special configuration instructions to allow VPN traffic coming in the external interface to be routed back out that same external interface.  In Cisco it's "same-security-traffic permit intra-interface" (or "inter-interface", depending on the setup).  I don't know about the Palo Alto firewall, it might not need any special configuration.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now