02-28-2006 06:54 AM - edited 03-03-2019 11:54 AM
I have the following setup and wanted to make sure what I am conceptually doing is correct:
t1-1760router--2950switch---pix501
t1:
254 available ip's
1760 router
-no changes, just connected to the catalyst 2950 switch
2950 switch:
-Fedora Linux server for web hosting
-Windows Server 2003 Nic 1
-pix501
Pix501:
dhcp turned off
-windows server 2003 nic 2
-2 workstations
-network printer
Server 2003:
dhcp server
dns
vpn
terminal services
workstation access
Nic 1
terminal services
WAN access
Nic 2
LAN workstation access
vpn
Does this setup look correct?
thank you in advance
03-06-2006 09:22 AM
L2TP extends the Point to Point nature of PPP by providing an encapsulation method for sending tunneled PPP frames, thereby allowing the PPP endpoints to be tunneled over a packet switched network. This is most commonly deployed in remote access type scenarios using the internet to offer intranet type services; a concept of a Virtual Private Network (VPN).
The two primary physical elements of L2TP are the L2TP Access Concentrator (LAC) and the L2TP Network Server (LNS).
LAC - The LAC is a peer to the LNS, acting as one side of the tunnel endpoint. The LAC terminates the remote PPP connection and sits between the remote and the LNS. Packets are forwarded to and from the remote connection over the PPP connection. Packets to and from the LNS are forward over the L2TP tunnel.
LNS - The LNS is a peer to the LAC, acting as one side of the tunnel endpoint. The LNS is the termination point for the LAC PPP tunneled sessions. This is used to aggregate the multiple LAC tunneled PPP sessions and ingress into the Private Network
03-06-2006 08:03 PM
Looks decent mate
Make sure you place the web servers, workstations and internet traffic (i.e. the T1) on separate vlans just for better traffic optimization and configure intervlan routing (with a simple access list) for management.
If youre looking @ actually deploying 254 workstations, you might consider making separate vlans as well based on departments or other criteria to optimize the broadcast domain.
HTH
Arvind
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide