Solved

Bridging 2 separate networks, same location

Posted on 2011-09-10
8
488 Views
Last Modified: 2012-05-12
Hello all.
I feel like I should know this, but I don't.
I have 2 separate networks in the same building.
Each has its own internet connection with static IP and an Untangle Server running as a router. Each has its own SBS2008 server running DHCP, DNS, Exchange, IIS web app, SQL database, etc..
One network is 192.168.0.x and the other is 192.168.10.x.
We need the 2 networks to communicate with each other quickly.
I have a site-to-site VPN with the Untangle Servers' OpenVPN. It works, but running RDP or terminal services across the network is painfully slow. I'm getting lots of complaints.
Also we have an IP phone system on the 10.x network, and if phone is plugged into the 0.x network, the phone "cuts out". Right now all phones are plugged into the 10.x network, but that requires 2 ports for every desk that should only be on the 0.x network.
I'm assuming most of the problems are due to the slow internet connections, a 2mbps DSL on each side.
We have a 48 port PoE switch and a 24 port gigabit switch on each network. We're running out of ports on the PoE switch on the 10.x network, since both sides have their phones connecting through that switch.

Since both networks are in the same building (all cables meet in the same server room), shouldn't I be able to use some kind of "bridge" and scrap the site-to-site VPN? It seems to me I should be able to connect these 2 networks at gigabit speed instead of 2mbps tops.

Also, are there some unintended consequences to bridging the networks? I do not want a DHCP, DNS, or Exchange nightmare.
0
Comment
Question by:MeanJim
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 8

Expert Comment

by:nwtechdesk
ID: 36516581
You have at least two separate issues here.  Given that you want to use a single wire for pc and phone and that some pc's are on a different subnet the best answer is to put this all on the same subnet.  This will not interfere with the domains.  You will have to assgn a single DHCP and disable the other.  The main DHCP should be 10.x since the phones will assign themselves.  The 0.x system will have to use PC's w/ DHCP disabled and manually assigned the alternate server, dns and router.
0
 
LVL 3

Accepted Solution

by:
weedhell earned 250 total points
ID: 36516625
first question are the clients allowed to communicate with both networks or they should only connect to the service that you want to share? cause if the connections between clients in different  sub-nets isn't a problem you should be able to make this two networks work with no problem if you connect both servers to each other in same sub-net ranges... you can use a cross-over cable between two networks adapters one in each server both adapter should be in a different range but still in same sub-net something like this, one with  ip 192.168.15.2 subnet 255.255.0.0 and the other with 192.168.15.3 with subnet 255.255.0.0... After that select both adapters the one with connection to internet and the one with cross over configuration click with right button in one of the two and click in bridge.
 you should reconfigure dhcp servers to this:
 
dhcp server 1

 server ip                   192.168.10.xx
 subnet mask             255.255.0.0
 server gate way      192.168.10.x
 dns server                192.168.10.x


dhcp server 2

 server ip                   192.168.0.xx
 subnet mask             255.255.0.0
 server gate way      192.168.0.x
 dns server                192.168.0.x


Make sure you use gigabit adapters in cross over connection to use a 100M/s connection speed between servers... take note that with this configurations you will not have two networks but only one... still with both dhcp servers working at different ranges your services shouldn't mess with each other. and voip phones will be able to connect to switch 1 or 2 just your choice...
0
 

Author Comment

by:MeanJim
ID: 36516801
Interesting responses.

We have two separate internet connections with public IPs and exchange servers, so I'm not putting them all on the same LAN and hard-coding all the IPs on half the computers and phones. The internet is slow enough as it is, so I don't want to put both networks behind the same internet connection.

The crossover cable between server NICs idea.... sounds like it would work, but isn't there some kind of device I could put between the switches that would accomplish this...... without mucking up the network properties on the servers? Both servers have 2 NICs in use already with virtual machines and Windows client-server VPNs already using them. I'm not comfortable adding a NIC and bridging them.

0
 
LVL 3

Expert Comment

by:weedhell
ID: 36516953
can you give all routers and switches models? there are a chance with rip protocol, that could make both networks recognize them self and that way make them connect... still you will need to change dhcp configurations... depending on your Router Adsl/cable brand and model there's a big chance that you can connect a cable between both instead of adding a nic and bridging from server... You said...
Each has its own internet connection with static IP and an Untangle Server running as a router (which equipment have the underlined function?)
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 8

Expert Comment

by:nwtechdesk
ID: 36516962
With the scheme I'm suggestng, there would be two internet connections.  Your 192.168.10.x would have a DHCP server but it would crowd all the phones and pc's onto a range of .2 - .100

Your secondary system would use 192.168.10.200 as your router, the server would be 192.168.10.201.  The PC's using this system would not be able use DHCP but are easily configured.  It is still one network but with two servers, two exchange servers, two routers.
0
 

Assisted Solution

by:lefodnes
lefodnes earned 250 total points
ID: 36516992
I am not familiar with Untangle that you have. This is probably also possible on that software.

I would buy two Sonicwalls TZ 190 / TZ 210, both with Enhanced OS. They have three "legs" or ports that you can route traffic. The LAN and WAN ports are as similar ports you find on any standard NAT router. But there is a second port called OPT, on which you can route the traffic from 0.x to 10.x and vice versa. This way, you don't have to touch any settings on the servers, but you have to replace the untangle servers, and you would loose the OpenVPN, but the Sonicwalls do have VPNs also.

Maybe you can do the same with Untangle Server ? I'm not familiar with that, but after looking at their website, it looks quite easy to install an extra NIC into both the Untangle Servers, and use their Router virtual rack component.Then connect both new NICs with a cable, and probably some static routing in the Untangle.

A cheaper and simpler solution would be to just interconnect the two networks with a single router home router. Depends a little on which services you need. If it's just RDP, and there is only one RDP server, it is very easy to just interconnect those two networks by setting the home router's LAN port on the network that has the RDP server, and the home router's WAN port on the other network. Then you would have to give the WAN port an ip that works on that network, and the LAN side an IP that works on that network. Also you would need to turn off the default DHCP in that box, and add a Virtual Port for the rdp port.

I hope that one of my three suggestions will lead you further down the road.
0
 

Author Comment

by:MeanJim
ID: 36517178
Thank you all for your thought-provoking responses. I will let you know how it all goes.
0
 

Author Closing Comment

by:MeanJim
ID: 36547082
What I ended up doing....

I added a NIC to each Untangle server. I gave one the address 192.168.2.1 and the other 192.168.2.2. I connected them with a switch (didn't have and couldn't make a long enough cross-over cable at the time, but I'll eventually do that because I want my 8 port gig switch back), set up static routes and bypass rules in Untangle, shut down the VPN (on both Untangles), and there it went. I copied a 138MB file in less than 10 seconds from 1 LAN to the other. Haven't tried the phones yet from the other side, but feeling very confident.

Thanks for pushing me in the right direction!
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
If you are thinking of adopting cloud services, or just curious as to what ‘the cloud’ can offer then the leader according to Gartner for Infrastructure as a Service (IaaS) is Amazon Web Services (AWS).  When I started using AWS I was completely new…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now