Solved

Using static internal IPs through two VPN devices

Posted on 2013-05-29
7
340 Views
Last Modified: 2013-10-14
I have a group of users who are assigned static IPs when VPNing into our network, in order to accurately send them audio/video streams.  They are getting assigned 192.168.7.x IPs.  Routing for 192.168.7.x on our internal core switches points towards our single VPN endpoint.

I would like to configure a backup VPN endpoint that might be used by these users.  I can assign them their 192.168.7.x IPs through RADIUS, but how would my routing work?  My core switches are currently pointing towards the existing VPN device for 192.168.7.x addresses.  Is there any way to tell them that 192.168.7.x address might be through VPN device 1, but might also be through VPN device 2?  Thank you for any help that you can provide.
0
Comment
Question by:sloth10k
  • 4
  • 2
7 Comments
 
LVL 69

Expert Comment

by:Qlemo
ID: 39206167
You can provide a route to the other device, with a higher metric (TTL). However, that requires that the link to the primary VPN router goes down, or an according ICMP message is sent back from that router if the VPN is not available.
0
 

Author Comment

by:sloth10k
ID: 39208395
As you point out, that solution would require sort of an all-or-nothing cutover between the two devices.  I am looking for a solution where the two VPN devices could be used in parallel.  For example, remote users on a certain ISP cannot access VPN device 1, but they can access device 2, because the two devices are on different carriers.  Thanks for the suggestion.
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 39208412
A route can always point to a single gateway only. The info of where a incoming packet was coming from (which router etc.) is not available (or ignored), so a "return same way" approach is not feasible.

I assume the association between client and ISP (and hence device to use) is static? Then you should be able to split the .7 network in subclasses reserved for each VPN device, and create routes accordingly. Instead of subclassing, different VLAN tagging might be working, too.
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:sloth10k
ID: 39216603
Unfortunately, the association between client and ISP is not static.  It's possible that any remote client may need to come into either of the two VPN devices.
0
 
LVL 69

Accepted Solution

by:
Qlemo earned 500 total points
ID: 39217455
Then "You can't do that" seems to be the appropriate answer ...
0
 
LVL 1

Expert Comment

by:terminal_dk
ID: 39218253
The only solution is the split 192.168.7.x into 2 subnets, and assign IPs depending on what VPN router the user hits. So on VPN he might get 192.168.7.3 and on VPN2 me might get 192.168.7.131.
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 39571642
terminal_dk,

The asker insists on having static IPs, with "dynamic" ISP. Subnetting has been suggested already, but is not available because of the non-static ISP association.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question