Solved

VPN 2 Offices with Same IP Range/Subnet

Posted on 2011-02-17
4
544 Views
Last Modified: 2012-05-11
I have two offices setup with the same IP Range/Subnet: Office A (XYZ.Ohio) 192.168.1.0/24, and Office B (XYZ.com) 192.168.1.0/24 - both have Server 2003 DC running AD.  Office A has a SQL 2005 and SQL 2008 servers, and Office B is running an Exchange 2003 server.

I want to setup a VPN between Office A and B so I know I have to change the subnet on one, but since they are both using the most common range I'm thinking of changing both to an uncommon subnet since VPNing into either has caused issues for remotes.  

My questions: 1. how involved is it to change the IP addresses/subnet on an AD network, running exchange and SQL servers, both DCs running DHCP server.
2. - what would be an uncommon and suggested subnet/IP ranges to use so we dont' confilict when Remotes VPN in to either office or conflict between offices.
0
Comment
Question by:dhas
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 125 total points
ID: 34916761
I'll throw in my 2 cents....  

For the vpn issue, there are methods to vpn together 2 LANs with overlapping subnets.    IF you use cisco gear, this is well documented and I can provide links to the HOW TOs for this.  

If you want to change subnets, I usually shy away from the common ones that most comsumer routers would use.   So I tend to use 192.169.50.x/24,  192.168.51.x/24, etc.     Alternatively, use a 10.1.1.x, 10.1.2.x, etc...      

Changing a whole subnet to a new Range can be a little tricky.   I'm sure you can find better documentation on the process, but basically:
1) identify the subnets to change
2) select new range
3) identify any static assigned IP, identify any IPs with reservations
4) Set the DHCP lease time very low, like 3 hours.  So clients will frequently try to obtain new leases.
5) That night, canvas the subnet, redo the statics to the new range,
6) Create/activate the new dhcp range, create the new reservations.   ou will have new DNS and WINS servers most likely
7) Change the server's IPs make sure that AD DNS is updating as well.  Check and double check DNS
Follow MS's processes on changing the DC to a new subnet , there are articles covering this, just google it.  


0
 
LVL 3

Expert Comment

by:goldeneagle3333
ID: 34916766
If you are using DHCP it should not be that complex.  I would make a list of all the static IP's and plan everything out in detail.  It is more complex to setup a site-to-site VPN.  
0
 
LVL 7

Expert Comment

by:Cuteadder
ID: 34916786
1. Change the dhcp range, change all the static ip's on the servers

2. Use a 10.*.*.* ip range
0
 

Author Comment

by:dhas
ID: 34925524
Thanks all.  I'm planning on using the 10.1.X.X range.  

I'm having difficulty finding any technet articles on changing the DC to a new subnet... but I'll keep looking.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
eigrp in site-to-site vpn 4 76
VLAN Question 7 44
Remote desktop connection frequent connection lost 5 54
SBS2011 VPN users no longer connecting 4 34
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question