Solved

Network routing.

Posted on 2012-03-09
3
349 Views
Last Modified: 2012-03-12
Hello:

Previously, our Corporate network only had 1 VLan, with a /24 subnet(256 IP's).  We were running out of IP addresses; hence, I thought it best to make 2 additional Corporate VLans.  To have:

VLan-1 = Miscelaneous non-intelligent devices (Printers, electrical panels, etc). (192.X.X.X/24)
VLan-2 = Microsoft Windows Domain PC's (10.X.X.X/24)
VLan-3 = Servers. (10.250.X.X/25)

The above system has worked well for segmenting the different parts of the network, in addition to freeing up some much needed IP addresses (on VLan-1).  I have created network routing rules, on our main router, to allow network traffic to be routed between V-Lan’s.

Anyway, I could not bring over some of the Microsoft Windows Domain PC's to VLan-2 because these Specific PC's had some proprietary software installed on them that must communicate to the Vendor’s router that is also on VLan-1 (192.X.X.X/24).  Additionally, the vendor's router has an Access Control List (ACL) that only accepts traffic from a specific IP address list.  


I have manually created static route's, on those specific computer's route table, to redirect network traffic to the Vendor's Router on VLan-1. Ie  route ADD 29.X.X.0 MASK 255.255.255.0 192.X.X.100 -p  

My question is:  What must I do to allow the PC's, with the proprietary software installed, to be moved to VLan-2 and still communicate with the Vendor’s Router on VLan-1?  It might be important to mention that the Vendor's Router is on a 192.X.X.X - IP scheme and the other VLan is using a 10.200 - IP scheme.
0
Comment
Question by:Pkafkas
  • 2
3 Comments
 
LVL 1

Author Comment

by:Pkafkas
ID: 37703150
I think I might have to:

1.  Submit a request to the Vendor to create 2 new IP addresses in the router's Access Control List (ACL).
       a.  The new IP addresses will need to be in the 10.200.X.X/24 IP address scheme.  

2.  I though about only doing 2 PC’s at first for testing.
       a.  Then after a couple of months to begin changing over half of the other PC's with the proprietary software.

3.  Instead of using a static Route, on the PC itself, I would need to make a static route rule on my company's Corporate router.  
       a.  Not the Vendor's router, my company's corporate router.
       b.  The same router where rules are in place to allow network traffic between the different VLan's.
0
 
LVL 17

Accepted Solution

by:
lruiz52 earned 500 total points
ID: 37704375
Your plan sounds good, but your vendor will also need to add a static route to the 10.x.x.x/24 network, so request that also.
0
 
LVL 1

Author Comment

by:Pkafkas
ID: 37712546
Thank you for the feedback.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Draytek (Site to Site VPN using IPSec) 6 62
VOIP gateways - feedback 23 64
Dlink-DIR 816 router 4 40
Netflix streaming problem 18 62
The use of stolen credentials is a hot commodity this year allowing threat actors to move laterally within the network in order to avoid breach detection.
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question