Jump to content

Best setup for routing between 6 subnets plus internet?


Recommended Posts

Posted

Hi all,

 

There is a chance that we might end up with up to 5 feeder schools connecting in to our site via leased lines, and we would house various services here for them to access and be used as a gateway for internet access. The schools also need to have the option of being able to connect to each other. Each school has its own subnet, so I'm thinking that I would need to be able to route between the 5 schools, a DMZ, and the internet.

 

My question is: what is the best way of achieving this? Does anyone know of any particular hardware that would handle this well?

Posted
Sounds like its a VPN connection setup that is needed (all feeding into your main site) - this way you could share secure services without having them posted on the internet.
Posted
I don't think I understand why a VPN would be necessary? The connections between the schools would be via leased line, direct in to the school and not over the internet. In that respect it would already be a private network. I might be missing something, but I think the issue is finding the best way of routing between so many subnets.
Posted
Yes, but which! I know my way around IPCop but that only supports 4 interfaces, and I have no experience of anything that might be able to handle 7.
Posted
Yes, but which! I know my way around IPCop but that only supports 4 interfaces, and I have no experience of anything that might be able to handle 7.

 

pfSense might be able to handle a few more interfaces than IPCop, could be worth a look

  • Thanks 1
Posted
Each satellite site needs a router. This will be your gateway for the subnet at each site. These pass traffic on to your main site. Your main site needs the same setup however it also needs static routes setup to route the traffic from the satellite sites in/out through the main site. Things get a bit more complex if you have a DMZ or if you want the satellites to be able to talk to each other. But that's the basic idea.
Posted
I don't think I understand why a VPN would be necessary? The connections between the schools would be via leased line, direct in to the school and not over the internet. In that respect it would already be a private network. I might be missing something, but I think the issue is finding the best way of routing between so many subnets.

 

Do ignore my post :) I thought the lines were just out onto the web and not direct into the school site.

Posted
Each satellite site needs a router. This will be your gateway for the subnet at each site. These pass traffic on to your main site. Your main site needs the same setup however it also needs static routes setup to route the traffic from the satellite sites in/out through the main site. Things get a bit more complex if you have a DMZ or if you want the satellites to be able to talk to each other. But that's the basic idea.

 

Actually this was another thing that I wasn't certain of - if each satellite site needed a router also. I haven't dealt with leased lines before but as I understood it they are just glorified fibre links. I figured that because you don't need a router to link two buildings with fibre, that I wouldn't in this case either and that I'd only need a router to handle traffic between the subnets. Did I get this wrong?

Posted

We have a TalkTalk Business MPLS circuit connecting all of our remote sites together, private IP addresses at each site all routing to each other through HP L3 switches.

The core switch at each location is the gateway address.

 

We all share a common Sonicwall Firewall managed by us to enable NAT/PAT from Firewall to any segment/host.

 

Mitel 3300 Phone systems at each site all linked to create a common voice platform over the MPLS.

 

The only problem with the entire system is TalkTalk... but thats another story.

Posted
Actually this was another thing that I wasn't certain of - if each satellite site needed a router also. I haven't dealt with leased lines before but as I understood it they are just glorified fibre links. I figured that because you don't need a router to link two buildings with fibre, that I wouldn't in this case either and that I'd only need a router to handle traffic between the subnets. Did I get this wrong?

 

In the fibre case you cite routers aren't required because both building networks are on the same subnet. This is not the situation in multi-site setups as you put each site in its own subnet with its own router to route traffic in/out of the site as required. You do this because you don't want your (slower) intersite link bogged down with broadcast traffic (which is what would happen if you didn't subnet and route between your remote sites).

  • Thanks 1
Posted

Pfsense all the way - it will do what you want plus more - there are hundreds of packages to install too for monitoring etc etc so you could monitor each connection and there are packages in there for MPLS and OSPF etc etc

 

We have Pfsense boxes running networks at remote locations and have done for a long time.

 

It's free and does the job nicely, all you'll need is an old PC with enough NIC's.

Posted
Ah, good thinking on the broadcast traffic - that would be the point that I'm missing so I'd definitely need a router at each site. Then if I'm thinking right, I would need a suitable router to handle traffic between the different sites, and also out on to the internet. It's not exactly the most simple setup, but I think I'm getting my head around it :confused2:
Posted
It really depends on the speed of the links between the sites as to if broadcast traffic is a problem. The worse culprits are Windows PCs network discovery, printers, bonjour and ARP. IPX/SPX used to be terrible too, but hopefully everyones killed that off by now? :D
Posted
Are you going to move everyone to a single AD as well?!! Also the router/firewall needs to be a comertially supported product. You could also deploy a single web filtering system at the gateway. I would also route a managemt network to you system as well so you can manage the firewalls deployed at the other sites.
Posted
Ideally you'd use a forest AD configuration. As you'd want to keep each site as a seperate domain in AD but be able to manage the whole AD forest if requred from the main site? I believe there's a few LEA's setup this way with their schools....
Posted

I'm not sure about the speed of the connections - I'm hoping for 100mb but I haven't had quotes in yet. Linking the ADs as a forest may be an option at some point but the main objective is to provide schools with internet access, secure access to a central finance system, email, and possibly remote backup and linking phone systems over VOIP (depending on what connection speed we end up with). It's all delightfully extravagant which means that it probably won't happen. :)

 

On the subject on web filtering, it would be nice if each school was able to set up and manage their own white/blacklists. I figured a nice way of achieving that might be to route each school out on a different public IP and use OpenDNS. Another reason for the separate public IPs is that some providers of online material restrict access by IP address and they get a bit uptight if your IP is shared with other schools.

Posted
I'm not sure about the speed of the connections - I'm hoping for 100mb but I haven't had quotes in yet. Linking the ADs as a forest may be an option at some point but the main objective is to provide schools with internet access, secure access to a central finance system, email, and possibly remote backup and linking phone systems over VOIP (depending on what connection speed we end up with). It's all delightfully extravagant which means that it probably won't happen. :)

 

On the subject on web filtering, it would be nice if each school was able to set up and manage their own white/blacklists. I figured a nice way of achieving that might be to route each school out on a different public IP and use OpenDNS. Another reason for the separate public IPs is that some providers of online material restrict access by IP address and they get a bit uptight if your IP is shared with other schools.

 

 

Ok, I'd stick with my original suggestion then. Subnet your sites seperately then use a router + firewall + proxy at each site to route and control the traffic going between them. I wonder if a smoothwall box is up to this?

 

As for your public IP, it will all be natted from the main site. However there's no reason why you couldn't have each router/firewall having a public IP and routing each sites internet traffic out of its own public IP.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...