Solved

Point to Point Connection with remote site.

Posted on 2010-09-01
3
450 Views
Last Modified: 2012-05-10
Hello Experts:

I have a remote site that is using a DSL line and we here at the corporate office have a 3 meg t-1 line.  I need to funnel all the internet traffic from the remote site into the corporate site so they can be monitored while using the internet.  What do I need (hardware)  to set up a point-to-point connection so that their traffic is routed to us?  For the corporate office, I am looking to replace my SG-5 juniper router with a Palo Alto Firewall.

Thanks
0
Comment
Question by:huntersp3
3 Comments
 
LVL 22

Assisted Solution

by:Matt V
Matt V earned 50 total points
ID: 33580971
You just need a small branch office router at the other end and setup an IPSec VPN tunnel back to home office.  Make the branch router use the main office as it's default route.
0
 
LVL 63

Assisted Solution

by:SysExpert
SysExpert earned 50 total points
ID: 33580984
Well your Juniper could handle this by adding a small netscreen ( NS 5 GT 20x or similar ) at the remote with a VPN tunnel to the office for all Internet traffic.

May also work with any router that can handle a VPN tunnel ( most can )

I hope this helps !
0
 
LVL 3

Accepted Solution

by:
agaskill707 earned 400 total points
ID: 33581093
Any firewall that can do IPSec should do fine.  You can set up an IPSec tunnel where the far end of the tunnel (as the remote side sees it, to the corporate side it would be the near end) is the default network (0.0.0.0/0), which will make all internet traffic come through the IPSec tunnel to the corporate office and then go out the connection there.  Different firewalls might have their own nomenclature for such a tunnel configuration, but fundamentally that's what it is.  Two things to be aware of: 1) Internet access from the remote office will be using double the bandwidth at the corporate office, once to come in from the internet and once to go out to the remote site.  Of course T1s are full duplex, so they can potentially download at 3Mbit, it's just that it will be saturating both inbound and outbound bandwidth at corporate.  2) Some firewalls need special configuration instructions to allow VPN traffic coming in the external interface to be routed back out that same external interface.  In Cisco it's "same-security-traffic permit intra-interface" (or "inter-interface", depending on the setup).  I don't know about the Palo Alto firewall, it might not need any special configuration.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Hello All, I have been training on Multicast for a while now and whenever I start the topic , I find out that my friends /  Colleagues mention that they do not know how to test Multicast Joins. As most of the multicast would be video traffic and …
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now