Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN and EoIP (Ethernet over IP)

Status
Not open for further replies.

DeeBeeTee

IS-IT--Management
Mar 6, 2006
3
CA
Hi All,

I am looking to upgrade the VPN connection I have with a remote office location with a goal to bring the subnet at that location into the head office and connect it physically to our primary firewall / router.

Clearly, a site-to-site VPN must have different subnet addresses at each end which has lead me to search for technologies allowing Etheret bridging using the Internet as the bridging conduit.

So far It appears only a company in Latvia called MikroTik actively promotes their protocl (EoIP) which appears to do exactly what we need.

My question, I suppose, is does anybody have experience with this type of configuration and if so, what technology was employed to make this happen? Also, any suggestions on how else I could achieve this goal would be greatly appreciated.

Cheers,

Dan.
 
We did it with Cisco VPN connection. We had all of the machines connect across VPN to the DC and we set aside a range of ip's in the same subnet for that office.
 
Well my DC for that office is over there as I cannot afford the banwidth overhead of authentication and the like. But im interested at how you made it happen exactly.. What do the PC's in the remote office use as their gateway? How does the VPN device know to route the traffic through the VPN tunnell for specific IPs within the same subnet? These are the problems Im faced with and cannot seem to resolve.

Cheers,
 
At the remote office I have a PIX501 but am ready and willing to upgrade that if required. At the Head Office End I am using a Proventia M50 managed security appliance that is hosting the VPN endpoint. In a perfect world, I would host this endpoint using a seperate VPN device (Most likely identical to the once I get for the remote end) and then Physically plug the remote office into an interface on my M50 and therefore allowing the remote users to use this device as theire gateway. This will make my security and web traffic control management much more streamilined.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top