11-28-2007 09:31 AM - edited 03-03-2019 07:43 PM
We currently have a 1700 Router with 1 T1 WIC.
We have a T1 running between the 2 offices with netscreens handling the VPN. The big bossman wants faster internet and wants a to drop comcast business in and I can't imagine that this would be that difficult to do, but I just can't figure it out. I did the CCNA 5 years ago, but I never did anything with it so I don't know what I am reaching for.
I want all VPN traffic to go out over the T1 and everything else over comcast. I know this is possible, but I can't remember the specifics.
Please enlighten me! Thank you so much.
11-28-2007 10:54 AM
Matthew
Your post seems to describe two offices connected by T1 and running VPN over the T1. It does not describe how you currently have Internet connectivity. Knowing this might help in knowing how to best answer your question.
It seems to me that there are several aspects to consider about what you want to implement. First there is how you will establish the new connection. You have not told us what kind of interfaces are on the 1700 other than that it has a T1 WIC. The Comcast will probably use an Ethernet connection. Do you have an available Ethernet connection on the 1700?
After you get the issues of how to connect to Comcast resolved there will be issues of how you get VPN traffic to go over the T1 and everything else to go over Comcast. It might be as simple as configuring a default route pointed out Comcast and configuring routes for the VPN destinations pointing out the T1. Or you might need to configure Policy Based Routing. PBR allows you to make routing decisions based on characteristics of the packet, so you could use PBR to identify the VPN traffic and send it over the T1.
HTH
Rick
11-28-2007 11:52 AM
I made a quick diagram of the network. In my defense, I inherited this :-)
I will have to check and see what is available on the router, I can't remember at this time. Comcast will supply me with a modem and I know that it is ethernet.
Well I was thinking IP routes would work, however now that I think deeper into it, from looking at netflow information everything hits the NetScreen before it goes to the router so it has the netscreen IP address, but the servers have their own public IPs, which might work. Because I don't care if people log into the Terminal Server through the T1.
I will try and get the info you wanted from the router, i'm offsite today. Thanks for your help!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide