Solved

Topology for two gateways and MPLS in a single LAN

Posted on 2010-11-09
5
809 Views
Last Modified: 2012-05-10
Hi Experts,
We are about to move on to deploy MPLS (with SIP, internet). The MPLS will co-exist with the currently-existing Verizon internet T1 which will be disconnected while the 3 year contract expires next year. I'm very confused about how the two gateways are going to co-exist. Please help me figure if this topology is going to work.
As you can see on the attached file, there will be two gateways -- each from different ISP. Each firewall will be the gateway and handle NAT.
In this case, in order to make the two gateways available to all computers inside the LAN, should I connect Switch-1 and Switch-2? Does it make sense? If not, then how to have pc-A connect to the MPLS?

Stone-MPLS-with-Verizon-T1.JPG
0
Comment
Question by:Castlewood
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 8

Expert Comment

by:ShareefHuddle
ID: 34093805
Yes connect switches and in your Asa add routes to your 2610 for mpls subnets.
0
 
LVL 29

Expert Comment

by:pwindell
ID: 34094289
With a single-subnet LAN you should have done this below.  It requires creating an additonal Internal LAN Segment (example 10.10.10.x and 10.10.11.x).  The MPLS Router would have the LAN Interface set to run on the second IP Segment.



Simple-Single-Subnet-LAN-with-se.jpg
0
 

Author Comment

by:Castlewood
ID: 34116904
pwindell:
Thank you for the idea. But Cisco1841 has two ports -- port0/1 for SIP & Internet should be connected to Firewall while port 0/0 for MPLS should be to the LAN switch. All traffice to MPLS will be routed to my branch office site . Then what is your Second Internal Segment for?

With your idea, I come out with the following modified diagram. I kind of feel something not very right as the 10.10.10.2 become meaningless. And 10.10.11.x doesn't seem right either. Can you help?
Thanks bunch.
Stone-MPLS-with-Verizon-T1-2.jpg
0
 
LVL 29

Accepted Solution

by:
pwindell earned 500 total points
ID: 34120567
You have to keep the routing Symmetrical.

You can have separate lines on the outside of the 1841,...but not on the inside.  The PBX runs on the LAN the same way as everything else,...the "type" of traffic comming from it is irrelevant.  The traffic types won't be on separate lines untill after they leave to 1841 out into the MPLS Cloud.  You cannot have the line you show as "MPLS 10.10.10.3" in that above diagram,...the 1841 would have 3 lines,...2 T1'a on ther serial side and 1 on the Ethernet side going to the side of the ASA

You have a single subnet LAN,...therefore you can't have multple routing devices sitting on it at the same "level" unless you are going to go around and maintain individual Routing Tables on every individual Host,...that's what Asymmetrical routing causes (among other problems).

Therefore what you need is a single routing device (the ASA) on the LAN and any subsequent routing devices branching off of that one outbound downstream (the 1841).  This allows the single LAN routing device to make all the primary routing decisions.   That's symentrical routing.

The additonal secondary internal segment could just be a /30bit Point-to-Point between the ASA and the 1841,...or you can run it as a /24 segment and use it as a normal LAN segment for future growth.  Note,..that from the ASA's perspecitic that addtional LAN segment is not a DMZ,..it is just an additioanal trusted internal LAN segment.
0
 

Author Closing Comment

by:Castlewood
ID: 34343871
It should be PIX515E instead of 2610 in my diagram.
We ended up use two firewalls in this project to keep in only one subnet 10.10.10.0.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
spanning tree loop even though stp is enabled 10 82
BGP Local Preference 5 48
site - site VPN 3 42
How to disable sflow Cisco nexus 9k 3 17
This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
AWS has developed and created its highly available global infrastructure allowing users to deploy and manage their estates all across the world through the use of the following geographical components   RegionsAvailability ZonesEdge Locations  Wh…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question