06-05-2019 07:08 AM
Hi,
I am having brain fog and wanted to know what is the best way to setup routing between two sites that are connected via a 3rd party managed LAN extension.
The 3rd party is configuring all the site to site connectivity through their NTE and will plug straight into the 3850 on each side.
I will need to do the routing.
I have created layer 3 vlans which are similar to the current site, what is the additional config that is needed?
06-05-2019 07:14 AM
If you have configured L3 interface SVI already.
for secure connection
you can run ipsec between sites or to main site.
Create Access control protect between the links
06-05-2019 07:22 AM
Ok so the security if needed can be added at a later date, but the SVI's should be enough to talk to each site?
06-05-2019 08:50 AM
on high level YES, again we can only suggest based on the information you provided.
if you looking more help, good to have HLD diagram so we can suggest in better manner.
06-05-2019 11:45 PM
Hi, I've drawn out the diagram.
As mentioned the ISP with be doing the link from network one to two I will need to do the routing.
I am thinking I will need to create a new vlan interface on each side such as vlan 500 give it an new ip/subnet of 192.168.100.1/30 and then attach that vlan 500 to the access port linking the LAN extension?
06-06-2019 01:22 AM
Actually after reviewing the config the core 1 switch connects directly to the FirePOWER and the 3rd Party router such as the image attached.
the int it connects on is gi1/016 and its config is shown. Just a generic access port on vlan 902 nothing else using it.
What I would like to clarify is what is needed for the routing between the sites?
As mentioned the 3rd party is providing a managed LAN extension.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide