cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
272
Views
0
Helpful
1
Replies

VPN link with two Cisco 897VAG over 4G

mawright1
Level 1
Level 1

Hello, 

I hope someone can help.

I need to create a temp solution whereby using two Cisco 897VAG with 4G sim cards where i can configure a VPN back to the main firewall to get the remote site on the main network, but also too load balance the users across the two routers. 

The site will have approx 16-20 users and I believe one 4G connection wouldn't suffice for the amount of bandwidth required. 

Thanks.

1 Reply 1

Richard Burts
Hall of Fame
Hall of Fame

So it is a single remote site with 16-20 users which will have two 897VAG. You want some users to use router 1 to access HQ while other users use router 2 to reach HQ. There are several challenges that you must address to achieve this.

1) the first challenge is fairly straightforward and is to configure each 897 with a site to site VPN terminating on the firewall at HQ. (and configuring the firewall at HQ with VPN connecting to the two remote routers)

2) the second challenge is to get some users to go to router 1 while other users go to router 2. And I assume that you would like failover so that if there is a problem with router 1 all users would use router 2. I would suggest that for this you configure two HSRP groups. router 1 will be the active router in one group while router 2 is active in the second group. Some users will be configured with the virtual address of group 1 as their default gateway while other users default gateway will be the virtual address of group 2. This should allow splitting the traffic and also provide failover.

3) the third challenge is the most difficult. At HQ when you configure two VPN connecting to the remote both VPN will be trying to access the same remote subnet. And the result is that the firewall at HQ will try to send all of the traffic for the remote subnet using the first VPN. To solve this you may need to have one of the routers at the remote to do address translation. This will allow the firewall at HQ to believe that it is communicating with two remote subnets.

HTH

Rick

HTH

Rick
Review Cisco Networking for a $25 gift card