Jump to content

Recommended Posts

Posted (edited)
Let me know, as I'm trying to reproduce

 

Thanks

S

 

Hi,

 

I now messed up my previous setup so I think it's best to go back to basics regarding the network topology and what I'm actually trying to achieve here. I've attached a diagram with IP addressing. Ideal solution would be all networks to be able communicate with all subnets however I'd be happy if only the two outer networks could talk.

 

 

Some facts:

Server A

2 Network Cards

IP Addresses: 192.168.10.1 and 192.168.1.1

NAT running on 192.168.10.1 to provide internet running for 192.168.10.0/24

DHCP running for both networks

Windows Server 2008 SBS Std.

VPN Dial in for users is required too

 

Server B

2 Network Cards

IP Addresses: 192.168.20.1 and 192.168.2.1

NAT running on 192.168.20.1 to provide internet running for 192.168.20.0/24

DHCP running for both networks

Windows Server 2008 Foundation.

 

PCa1

IP Address 192.168.10.100

 

PCb1

IP Address 192.168.20.100

 

Router A

IP Address: 192.168.1.254

FQDN: RouterA.Domain.net

 

Router B

IP Address: 192.168.2.254

FQDN: RouterB.Domain.net

 

What I need to achieve:

Both outer NAT networks, in Red (ie, 192.168.10.0 and 192.168.20.0) able to reach each other across the Internet. I'd prefer the VPN to use Static IP addressing to avoid IP changes, if possible. So in plain English, anywhere within the 192.168.10.0/24 network able to connect to anywhere in the 192.168.20.0/24 network and vice versa.

 

I understand RIP maybe required on both servers to achieve 'the ideal solution'. - I did have this working with Static Routes but tbh I think I'd prefer to use RIP if its straight forward to do. (I know how RIP works etc, but always configured it on cisco equipment, never with RRAS)

 

 

Hopefully now you'll be able to fully understand the set up and how to assist me :) Can you please point me in the direction of setting this VPN connection up from scratch?

 

thanks,

Fraser

 

 

 

 

Edit:

 

After taking a wee break from thinking (it is 3.45am!) I've got the VPN up and running (without RIP - using static route). All devices can ping each other. As everything is working, I restarted Server B to test the connection is restored when reconnected. The results are below:


     
  • Site A can ping Server B and PCb successfully.
  • Site B can ping PCa successfully.
  • Site B (Server+PC) cannot ping ServerA

Then when I delete and recreate the static route on Server B;

Route delete 192.168.10.1

Route Add 192.168.10.1 mask 255.255.255.255 192.168.20.10.50 -p

...all starts working again. Why?? I'm banging my head off the wall here!

 

If I can't get this issue resolved, I think I'll redesign both networks, removing the seconds subnet and NAT interface at each site. It will be a pain in the ass to do, but might just be worth it in the long run!

 

Thanks

Fraser

Network Diagram.jpg

Edited by Fraser-09
Posted
Looking into this bear with me.

 

Sukh

 

 

I'm in the process of removing the outer subnets in the diagram. SiteB is already done (as its a small office) and I should have SiteA done by the end of the night. After that, it should be a doddle to create the Site-to-Site VPN. The network was set up this way by the installers as site A is part of a business centre so there was untrusted devices from other offices using the same network (192.168.1.0/24). Since then, SiteA has expanded and the other offices were moved to separate broadband lines.

 

Will keep you posted... I'll be here all night!

 

Thanks

Fraser

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...