Solved

VPN 2 Offices with Same IP Range/Subnet

Posted on 2011-02-17
4
537 Views
Last Modified: 2012-05-11
I have two offices setup with the same IP Range/Subnet: Office A (XYZ.Ohio) 192.168.1.0/24, and Office B (XYZ.com) 192.168.1.0/24 - both have Server 2003 DC running AD.  Office A has a SQL 2005 and SQL 2008 servers, and Office B is running an Exchange 2003 server.

I want to setup a VPN between Office A and B so I know I have to change the subnet on one, but since they are both using the most common range I'm thinking of changing both to an uncommon subnet since VPNing into either has caused issues for remotes.  

My questions: 1. how involved is it to change the IP addresses/subnet on an AD network, running exchange and SQL servers, both DCs running DHCP server.
2. - what would be an uncommon and suggested subnet/IP ranges to use so we dont' confilict when Remotes VPN in to either office or conflict between offices.
0
Comment
Question by:dhas
4 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 125 total points
ID: 34916761
I'll throw in my 2 cents....  

For the vpn issue, there are methods to vpn together 2 LANs with overlapping subnets.    IF you use cisco gear, this is well documented and I can provide links to the HOW TOs for this.  

If you want to change subnets, I usually shy away from the common ones that most comsumer routers would use.   So I tend to use 192.169.50.x/24,  192.168.51.x/24, etc.     Alternatively, use a 10.1.1.x, 10.1.2.x, etc...      

Changing a whole subnet to a new Range can be a little tricky.   I'm sure you can find better documentation on the process, but basically:
1) identify the subnets to change
2) select new range
3) identify any static assigned IP, identify any IPs with reservations
4) Set the DHCP lease time very low, like 3 hours.  So clients will frequently try to obtain new leases.
5) That night, canvas the subnet, redo the statics to the new range,
6) Create/activate the new dhcp range, create the new reservations.   ou will have new DNS and WINS servers most likely
7) Change the server's IPs make sure that AD DNS is updating as well.  Check and double check DNS
Follow MS's processes on changing the DC to a new subnet , there are articles covering this, just google it.  


0
 
LVL 3

Expert Comment

by:goldeneagle3333
ID: 34916766
If you are using DHCP it should not be that complex.  I would make a list of all the static IP's and plan everything out in detail.  It is more complex to setup a site-to-site VPN.  
0
 
LVL 7

Expert Comment

by:Cuteadder
ID: 34916786
1. Change the dhcp range, change all the static ip's on the servers

2. Use a 10.*.*.* ip range
0
 

Author Comment

by:dhas
ID: 34925524
Thanks all.  I'm planning on using the 10.1.X.X range.  

I'm having difficulty finding any technet articles on changing the DC to a new subnet... but I'll keep looking.
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
AWS VPS as AD Server 2 76
Setting up a VPN 60 179
SSIS with VPN COnnection 2 100
Palo Alto site-to-site vpn monitoring 5 13
OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
AWS has developed and created its highly available global infrastructure allowing users to deploy and manage their estates all across the world through the use of the following geographical components   RegionsAvailability ZonesEdge Locations  Wh…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question