Hi everyone, I hope you're all well. This is not so much a question, but I'd be interested to know your thoughts on best practice for a request I've been asked to work on.
Attached is a very crude network diagram (apologies!).
We have two DC's - DCR and DCS. We have a customer called Mobile City. Currently there's an IPSec VPN tunnel between Checkpoint DCR and Cisco ASA Mobile City. A lot of O365 traffic passes through this tunnel so it's rather risky not having any resilience. Hence, my request.
I've been asked to add a second tunnel between Checkpoint DCR and Cisco ASA Mobile City, then also two brand new tunnels between Checkpoint DCS and Mobile City. It's a fairly straightforward request but I just wanted to ask whether there are any best practices when it comes to this type of request.
My initial thoughts are that I will need the following:
- New interface with public facing IP address on DCR
- 2 x new interfaces with public facing IP addresses on DCS
- Can I use the LAN range (e.g. 172.10.3.0/24) in the existing tunnel for all four tunnels or would they need to be separate?
- Can the tunnels terminate on the same interface at DCR/DCS?
I'm confident I can get the tunnels up, but just wanted clarity on any further configuration on the LAN side, i.e routing.
Many thanks in advance.
B