Solved

Using static internal IPs through two VPN devices

Posted on 2013-05-29
7
305 Views
Last Modified: 2013-10-14
I have a group of users who are assigned static IPs when VPNing into our network, in order to accurately send them audio/video streams.  They are getting assigned 192.168.7.x IPs.  Routing for 192.168.7.x on our internal core switches points towards our single VPN endpoint.

I would like to configure a backup VPN endpoint that might be used by these users.  I can assign them their 192.168.7.x IPs through RADIUS, but how would my routing work?  My core switches are currently pointing towards the existing VPN device for 192.168.7.x addresses.  Is there any way to tell them that 192.168.7.x address might be through VPN device 1, but might also be through VPN device 2?  Thank you for any help that you can provide.
0
Comment
Question by:sloth10k
  • 4
  • 2
7 Comments
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
You can provide a route to the other device, with a higher metric (TTL). However, that requires that the link to the primary VPN router goes down, or an according ICMP message is sent back from that router if the VPN is not available.
0
 

Author Comment

by:sloth10k
Comment Utility
As you point out, that solution would require sort of an all-or-nothing cutover between the two devices.  I am looking for a solution where the two VPN devices could be used in parallel.  For example, remote users on a certain ISP cannot access VPN device 1, but they can access device 2, because the two devices are on different carriers.  Thanks for the suggestion.
0
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
A route can always point to a single gateway only. The info of where a incoming packet was coming from (which router etc.) is not available (or ignored), so a "return same way" approach is not feasible.

I assume the association between client and ISP (and hence device to use) is static? Then you should be able to split the .7 network in subclasses reserved for each VPN device, and create routes accordingly. Instead of subclassing, different VLAN tagging might be working, too.
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 

Author Comment

by:sloth10k
Comment Utility
Unfortunately, the association between client and ISP is not static.  It's possible that any remote client may need to come into either of the two VPN devices.
0
 
LVL 68

Accepted Solution

by:
Qlemo earned 500 total points
Comment Utility
Then "You can't do that" seems to be the appropriate answer ...
0
 
LVL 1

Expert Comment

by:terminal_dk
Comment Utility
The only solution is the split 192.168.7.x into 2 subnets, and assign IPs depending on what VPN router the user hits. So on VPN he might get 192.168.7.3 and on VPN2 me might get 192.168.7.131.
0
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
terminal_dk,

The asker insists on having static IPs, with "dynamic" ISP. Subnetting has been suggested already, but is not available because of the non-static ISP association.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now