Solved

point to point router configuration

Posted on 2011-09-26
4
280 Views
Last Modified: 2012-05-12
i have a few questions about a two site point to point setup.

background
i have two sites: site A - flat network - 172.17.x.x/18 - where the default gateway is the firewall.  site B - flat network - 172.16.x.x/18 - where the default gateway is the firewall.  we currently have a point to point t1 line in place, but it has been giving us problems.  it is a true T1 and was installed four years ago, so the equipment is aging - hence my post... i need to replace the routers on each end and verizon has not been very helpful with pertinent information regarding the circuit.

currently the point to point routers are configured with lan addresses on the inside and are plugged into the network (ex site A - has internal address 172.17.1.1, site B has internal address 172.16.1.1) and we manage the route through our firewall (routes on either end pointing traffic from one subnet to the next through the lan router address, but are tied to the default lan interface on the gateway).

my questions are:
is this the most effective setup?  i want to know if it would be better to configure the routers to be directly connected to our firewall/gateway and manage the route through the firewall interface (as opposed to the lan address and interface).  if so how should the addressing scheme look?

since this is a closed circuit, do i need ip information from my isp?  or can i make up arbitrary addresses on the same subnet on each end?

i have two cisco 1700 routers each with a csu/dsu card in it.  i'm pretty sure i need the csu/dsu cards to capture traffic on the point to point, but what is the right way to configure the wan(csu/dsu) interface and the lan interface?
0
Comment
Question by:jhaff
4 Comments
 
LVL 25

Expert Comment

by:Fred Marshall
ID: 36634551
It seems to me that this is a very reasonable topology.  I'm using exactly the same thing between 3 sites.

If it's a private link provided by the ISP - which may be called MPLS technology or a VLAN or .... then, at least in my case, the inter-office subnet is whatever you want.

So, I have
10.1.1.0 / 24
10.1.2.0 /24
10.1.3.0 /24
on the LAN sides.

There is an RV042 router at each side to interface to the links.
The inter-office subnet is:
192.168.223.0 /24

The respective RV042 addresses are:
192.168.223.1
192.168.223.2
192.168.223.3

Because these are not only inter-site links but also are internet links for two of the sites, the main site (with internet gateway) has the RV042 WAN pointing INTO the LAN and the LAN on the interoffice side.
At the other two sites, the RV042 LAN is on the site LAN and the RV042 WAN is on the interoffice side.

The only caution is that the firewalls may have stateful packet inspection on the LAN packets - which will block traffic from site to site.  This has to be turned off.
The RV042s are working in Router mode - no NAT.
0
 

Accepted Solution

by:
jhaff earned 0 total points
ID: 36718484
thanks for the response.  in my scenario each site also has its own internet connection.  i only want inter-site traffic to flow across the point to point.  

can i set it up like this:

inter-office subnet: 10.10.10.1/24 (site A) ------ 10.10.10.2/24 (Site B)

firewall interface address: 192.168.0.100 (site A) and 192.168.0.101 (site B)

then routes setup on each firewall that direct traffic from Site A to Site B through the P2P firewall interface address on firewall A, and vice versa, Site B to Site A through P2P firewall interface address on firewall B.

Or should the P2P routers just be plugged into the existing subnet (172.17.x.x at Site A and 172.16.x.x at Site B) and the route directs traffic to that internal lan address?

thanks!
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37068349
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now