Wednesday, March 4, 2020

Have I made a mistake in this design?

I'm reconfiguring the MSP I work for network, it's sat alongside the current setup so I can play about within reason with the config.

The new core is Huawei chassis switches, various firewalls hung off it and an OSPF relationship with connecting routers for ISP /internet access.

The transit between the switch and the routers is using an RFC1918 address. In testing client internet access everything works fine, but a test migration of a client with an AZURE VPN amongst others broke, all their internally hosted external webpages worked fine, as did internet access, but all the VPNs all dropped and wouldn't come back.up until.i reverted to the old setup.

The IP ranges used are identical new to old setup, the only significant difference is the transit IP range.

Should I have used an external address? Are the VPNs failing due to the internal subnet in use?



No comments:

Post a Comment