cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
247
Views
0
Helpful
4
Replies

Multi Network Site to Site

davidbl02
Level 1
Level 1

I have 3 sites, 1 HQ site with a static IP and 2 remote sites with dynamic IPs. Each site has 4 separate networks, all with the same address spaces. For security reasons, I only want 1 to have internet access.

Site one

network 1

VLAN 10, IP 10.10.0.0  255.255.255.0 No internet access

network 2

VLAN 2 data, 10.2.0.0  255.255.255.0 No internet access

VLAN 3 Voice, 10.3.0.0  255.255.255.0 No internet access

network 3

VLAN 12 data, 10.2.0.0  255.255.255.0  internet access

VLAN 13 Voice, 10.3.0.0  255.255.255.0  internet access

network 4

VLAN 200 data, 10.2.0.0  255.255.255.0  No internet access

VLAN 300 Voice, 10.3.0.0  255.255.255.0  No internet access

Site two

network 1

VLAN 10, IP 10.10.1.0  255.255.255.0 No internet access

network 2

VLAN 2 data, 10.2.1.0  255.255.255.0 No internet access

VLAN 3 Voice, 10.3.1.0  255.255.255.0 No internet access

network 3

VLAN 12 data, 10.2.1.0  255.255.255.0  internet access

VLAN 13 Voice, 10.3.1.0  255.255.255.0  internet access

network 4

VLAN 200 data, 10.2.1.0  255.255.255.0  No internet access

VLAN 300 Voice, 10.3.1.0  255.255.255.0  No internet access

and so on....

How many router will I need, and how can I connect the sites over the internet. I considered DMVPN, however I keep running into the problem of how to keep the separate networks from router to each other. I would like to have 1 VPN and trunk the other networks over network 3, the network that will have internet access.

4 Replies 4

Philip D'Ath
VIP Alumni
VIP Alumni

This is going to result in a complex configuration - something you probably don't want.

With only 2 remote sites I would renumber the conflicting networks.

Otherwise what you are going to have to do is NAT the conflicting address spaces to another address space first that is unique, and run that over the VPNs.

If you really don't want to renumber you could also look at using EasyVPN, which has some abilities to NAT subnets automatically.

http://www.cisco.com/c/en/us/products/collateral/security/ios-easy-vpn/eprod_qas0900aecd805358e0.html

I recommend you renumber the networks.

Could I use DMVPN?

You can use DMVPN if you make all the subnets unique.
Review Cisco Networking for a $25 gift card