Solved

Topology for two gateways and MPLS in a single LAN

Posted on 2010-11-09
5
806 Views
Last Modified: 2012-05-10
Hi Experts,
We are about to move on to deploy MPLS (with SIP, internet). The MPLS will co-exist with the currently-existing Verizon internet T1 which will be disconnected while the 3 year contract expires next year. I'm very confused about how the two gateways are going to co-exist. Please help me figure if this topology is going to work.
As you can see on the attached file, there will be two gateways -- each from different ISP. Each firewall will be the gateway and handle NAT.
In this case, in order to make the two gateways available to all computers inside the LAN, should I connect Switch-1 and Switch-2? Does it make sense? If not, then how to have pc-A connect to the MPLS?

Stone-MPLS-with-Verizon-T1.JPG
0
Comment
Question by:Castlewood
  • 2
  • 2
5 Comments
 
LVL 8

Expert Comment

by:ShareefHuddle
ID: 34093805
Yes connect switches and in your Asa add routes to your 2610 for mpls subnets.
0
 
LVL 29

Expert Comment

by:pwindell
ID: 34094289
With a single-subnet LAN you should have done this below.  It requires creating an additonal Internal LAN Segment (example 10.10.10.x and 10.10.11.x).  The MPLS Router would have the LAN Interface set to run on the second IP Segment.



Simple-Single-Subnet-LAN-with-se.jpg
0
 

Author Comment

by:Castlewood
ID: 34116904
pwindell:
Thank you for the idea. But Cisco1841 has two ports -- port0/1 for SIP & Internet should be connected to Firewall while port 0/0 for MPLS should be to the LAN switch. All traffice to MPLS will be routed to my branch office site . Then what is your Second Internal Segment for?

With your idea, I come out with the following modified diagram. I kind of feel something not very right as the 10.10.10.2 become meaningless. And 10.10.11.x doesn't seem right either. Can you help?
Thanks bunch.
Stone-MPLS-with-Verizon-T1-2.jpg
0
 
LVL 29

Accepted Solution

by:
pwindell earned 500 total points
ID: 34120567
You have to keep the routing Symmetrical.

You can have separate lines on the outside of the 1841,...but not on the inside.  The PBX runs on the LAN the same way as everything else,...the "type" of traffic comming from it is irrelevant.  The traffic types won't be on separate lines untill after they leave to 1841 out into the MPLS Cloud.  You cannot have the line you show as "MPLS 10.10.10.3" in that above diagram,...the 1841 would have 3 lines,...2 T1'a on ther serial side and 1 on the Ethernet side going to the side of the ASA

You have a single subnet LAN,...therefore you can't have multple routing devices sitting on it at the same "level" unless you are going to go around and maintain individual Routing Tables on every individual Host,...that's what Asymmetrical routing causes (among other problems).

Therefore what you need is a single routing device (the ASA) on the LAN and any subsequent routing devices branching off of that one outbound downstream (the 1841).  This allows the single LAN routing device to make all the primary routing decisions.   That's symentrical routing.

The additonal secondary internal segment could just be a /30bit Point-to-Point between the ASA and the 1841,...or you can run it as a /24 segment and use it as a normal LAN segment for future growth.  Note,..that from the ASA's perspecitic that addtional LAN segment is not a DMZ,..it is just an additioanal trusted internal LAN segment.
0
 

Author Closing Comment

by:Castlewood
ID: 34343871
It should be PIX515E instead of 2610 in my diagram.
We ended up use two firewalls in this project to keep in only one subnet 10.10.10.0.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Dell M6220 to Dell 6224 Port channel conundrum 5 26
Which NIC is live in Win/Linux? 25 87
Best sims for HP switches 4 39
extend vlan through a layer 3 connection 31 91
Introduction This article explores the design of a cache system that can improve the performance of a web site or web application.  The assumption is that the web site has many more “read” operations than “write” operations (this is commonly the ca…
If you are thinking of adopting cloud services, or just curious as to what ‘the cloud’ can offer then the leader according to Gartner for Infrastructure as a Service (IaaS) is Amazon Web Services (AWS).  When I started using AWS I was completely new…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now