Designing a hub and spoke vpn with 5510(Hub) and sonicwall tz100(spoke)
Currently we have a hub and spoke VPN network with ATT. They cost to much, so we decided to design our own VPN network.
ASA 5510 and multiple TZ100 (Sonicwall)
What I'm wrestling with is trying to understand how ATT is doing it.
We have the beginnigs of our network up. The ASA 5510, and 2 endpoints. ASA5505 and a TZ100.
Att's network consist of a Cisco VPN 3000 and numerious netgates (Sg7100). Those are rebranded snap gear or secure computing endpoints.
I've worked a bit with cisco getting the tunnels configured.
This is what I'm not understanding.
Here's a picture of the vpn network
/--- Netgate 10.40.45.1/24
CiscoVPN 3000 (192.168.199.2) ----netgate 10.40.46.1/24 (etc for all /24's in 10.0.0.0/8)
Also, I'm not sure if ATT set same-security-traffic permit intra-interface or I suspect it's the setting of OSPF and RRI that allows me at 10.40.45.1/24 to go over the VPN tunner to any endpoints on 10.0.0.0/8.
My network is not working like ATT has theirs set up.
1st. In configuring my network, cisco had me assign a static route in one of the endpoints (hub) to just reach the 10.40.45.1/24 from the 10.40.46.1/24 network. Moving forward, to reach 10.0.0.0/8 I can only assume I need to add a route fror 10.0.0.0/8 to reach the other enpoints from and other endpoint.
2nd. These ATT endpoints are not very configurable. Granted, ATT probably has it locked down with their firmware, but can't see ATT pre configuring the router with static routes. Their VPN 3000 in my opirion has to be updating the routes in the endpoint.
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...