cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
779
Views
5
Helpful
6
Replies

WAN access to a site local VLAN without a jump server, is it possible?

peter.slade
Level 1
Level 1

Looking for some thoughts;

We have multiple sites inter-connected on a WAN topology, each site having unique subnets.  At each site has a VLAN for VoIP service, but the VLANs for VoIP service are local to the site and currently can't be accessed from outside the site from another LAN across the WAN.

We have a couple of jump servers to remotely connect between a couple of the sites, but I was wondering if there is a WAN config that would allow a port or computer on a LAN at one site to connect to a VLAN at another site without going though a jump server?

I don't have enough background to know if this is possible, but thought I would ask.  Maybe I'm out to lunch or had too much coffee this AM...lol

Thanks

Peter

1 Accepted Solution

Accepted Solutions

mmm I see, that you should not be a good design, you could use a VPLS to interconnect this vlan but it should be new design just for that. 

Other option could be a NAT to translate the specific IP of the servers to other IP to be reachable. 




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

View solution in original post

6 Replies 6

Julio E. Moisa
VIP Alumni
VIP Alumni

Hi

Yes, you should be able to reach the voice service, trust me jumping servers is not a good practice, are you using MPLS to interconnect the sites? or it is through Internet or VPNs? the voice service should be advertised to the other sites through your WAN.




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Thanks for the reply Julio;

We use MPLS for connecting our sites.

Part of the problem is that they are creating the VoIP VLANs with the same IPs/subnets local on the sites, so the VoIP addressing for the VLANs at each site is 10.2.40.x

Peter

It would be better to use unique network addresses for the VoIP VLANs at both sites.

As workaround you can use L2TPv3 to make a pseudowire.

But, I think, you need additional physical interface to make it routed.

 

I agree about the unique config for the sites.  Wasn't my idea...

I'll read on L2TPv3 to see about the config to see if would offer a solution.

Thanks for the help.

Cheers

Peter

mmm I see, that you should not be a good design, you could use a VPLS to interconnect this vlan but it should be new design just for that. 

Other option could be a NAT to translate the specific IP of the servers to other IP to be reachable. 




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

I was not the one that spec'd the VLAN config and set it up this way, would have been much better to do right in the first place with the network config.

Thanks for the help, thought I'd see what others thought.

Cheers

Peter