cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
226
Views
0
Helpful
2
Replies

small network setup

solidground
Level 1
Level 1

I have the following setup and wanted to make sure what I am conceptually doing is correct:

t1-1760router--2950switch---pix501

t1:

254 available ip's

1760 router

-no changes, just connected to the catalyst 2950 switch

2950 switch:

-Fedora Linux server for web hosting

-Windows Server 2003 Nic 1

-pix501

Pix501:

dhcp turned off

-windows server 2003 nic 2

-2 workstations

-network printer

Server 2003:

dhcp server

dns

vpn

terminal services

workstation access

Nic 1

terminal services

WAN access

Nic 2

LAN workstation access

vpn

Does this setup look correct?

thank you in advance

2 Replies 2

thomas.chen
Level 6
Level 6

L2TP extends the Point to Point nature of PPP by providing an encapsulation method for sending tunneled PPP frames, thereby allowing the PPP endpoints to be tunneled over a packet switched network. This is most commonly deployed in remote access type scenarios using the internet to offer intranet type services; a concept of a Virtual Private Network (VPN).

The two primary physical elements of L2TP are the L2TP Access Concentrator (LAC) and the L2TP Network Server (LNS).

LAC - The LAC is a peer to the LNS, acting as one side of the tunnel endpoint. The LAC terminates the remote PPP connection and sits between the remote and the LNS. Packets are forwarded to and from the remote connection over the PPP connection. Packets to and from the LNS are forward over the L2TP tunnel.

LNS - The LNS is a peer to the LAC, acting as one side of the tunnel endpoint. The LNS is the termination point for the LAC PPP tunneled sessions. This is used to aggregate the multiple LAC tunneled PPP sessions and ingress into the Private Network

arvindchari
Level 3
Level 3

Looks decent mate

Make sure you place the web servers, workstations and internet traffic (i.e. the T1) on separate vlans just for better traffic optimization and configure intervlan routing (with a simple access list) for management.

If youre looking @ actually deploying 254 workstations, you might consider making separate vlans as well based on departments or other criteria to optimize the broadcast domain.

HTH

Arvind

Review Cisco Networking products for a $25 gift card