Solved

Question on Static Routing vs. VPN Connections

Posted on 2013-06-12
4
259 Views
Last Modified: 2014-03-03
Group, wanted to run a scenario by you and get your input. Here is our setup:

Site 1
Administrative LAN 172.16.8.1
Workstation VLAN 10.0.2.1

Site 2
LAN 192.168.10.0

I need to be able to connect the VLAN of site 1 to the LAN of site 2, currently we have an IPSec tunnel from LAN <--->LAN so the question is how to route the traffic. My question is this:

In Site 1 do I do a static route to force the traffic out?
Do I break the existing connection from LAN to LAN and do the Site 1 VLAN to Site 2 LAN VPN tunnel? Will it let me do a tunnel from a VLAN to a LAN?
Do I create a second tunnel from Site 2 to to both Site 1 LAN and VLAN?

Appreciate your time and input as always experts.
0
Comment
Question by:Ross Mccullough
4 Comments
 
LVL 18

Accepted Solution

by:
Sanga Collins earned 250 total points
ID: 39244038
If you already have a tunnel established and site 1 LAN can communicate with site 2 LAN and vice versa. Then all you should need is a new route at site 2 stating that all traffic for VLAN 10.0.2.1 should go through the existing tunnel.
0
 
LVL 38

Expert Comment

by:Aaron Tomosky
ID: 39244088
Agreed, its just a route and probably a firewall rule. No need for another tunnel
0
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 39244099
it depends on the type of firewall you have.

most firewalls and routers you setup a tunnel interface and then point routes at it like has already been mentioned.  In this case, just add another route pointing to the tunnel interface.  But make sure routing is setup on both sides so return traffic can get back.

however, i know that it doesn't quite work that way for the cisco PIX/ASA firewalls.  there you have to use the route that points you to the internet instead (usually the default route).  Then you have to create the ACL for nat 0 (nat exemption) and an ACL used to identify "interesting" traffic that is to go thru the tunnel.  In this case you just add the other subnets to the nat 0 ACL and the interesting traffic acl.  Then you kill the tunnel SA and let it form again by sending traffic that will be encapsulated in the tunnel.
0
 

Author Comment

by:Ross Mccullough
ID: 39244660
Group,
Thanks so much for your feedback. In our Site2 router (2911) I have added the follow inside the Static and Dynamic Routing but I cannot ping the VLAN gateway in Site 1 at 10.0.2.1 but can ping the LAN gateway via the VPN tunnel at 172.16.8.1. Thanks very much guys!

<Entry>
Prefix: 10.0.2.0
Prefix Mask 255.255.255.0
Forwarding (Next Hop) Interface
Forwarding Interface Gi0/0  (outside interface)
Metric 2
Permanent route <unchecked>
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
Security is one of the biggest concerns when moving and migrating your data from your on-premise location to the Public Cloud.  Where is your data? Who can access it? Will it be safe from accidental deletion?  All of these questions and more are imp…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now