General Networking Help

Dec 18, 2007 3 Replies

We are having an issue that I could use some help on.



We need to connect two networks together, we'll call them network 1 and network 2. I am an administrator on network 1 but not on network



  1. We've been provided an IP address for network 2 and a port on their main switch.


Our network (network 1) has a totally different set of network address (3 class C subnets) from network2. We'll say Network1's subnets are



192.168.64.X
192.168.65.X
192.168.66.X and Network2's subnet is
192.2.10.X


Network1 is configured in a star topoly with a mix of Cisco 6509 catalysts and Cisco 3550s. We have a central 6509 with a supervisor module setup as a basic router. The router inerface has the VLANs setup for each of our subnets.


Now here is the issue: We need to connect Network1 to Network2 in order to get out to a bunch of Web Based tools, websites etc. These networks are isolated and do not connect to the Internet in any way. Network2 is a network hanging off a larger logical network (not dissimliar to the Internet). This greater logical network we'll call InfoWAN. The Network2 has an establish pressence on the InfoWAN but Network1 does not. Our specific issues are: How do we route specific web traffic out Network 2 to get out to InfoWAN? How do we ensure that the web traffic knows how to return to a specific machine on Network1?


We have a Foundry BigIron 8000 at our disposal that may be used to connect the two networks.


If anyone has any help for us I would greatly appreciate it. By the way, I'm a point-and-click administrator (Windows admin). They cut our network engineer job a while so I'm pretty much up a creek.


Thanks, Mat


Turn up a layer 3 routing relationship between your (network 1's) 6500 and the router for network 2. Have your 6500 advertise network 1's class Cs, presuming there is no overlap in existing address space or the internet. If there is, use the 6500 to NAT the traffic into network 2, so that everything in network 2 (or the bigger entity) knows how to get back to the network 2 address that is the public NAT address for the network 1 traffic. Hope I haven't missed a requirement, does this sound feasible or am I missing something?

I appreciate the response. One issue I'm going to have is that we have a port on Network2's switch with no access to their routers. (I don't even think they have a router, they're routed to the InfoWAN (see above post) by a router that is not in their control). I understand what you're saying about NATing. I was reading a few things that led me to think that NATing would be necessary.

What if I use the BigIron 8000, configure a port for each network, setup a route w/ NATing? How do I route specific traffic to the internatl Network 1 port so it can be passed to network 2? I guess overall I'm a little baffled.

Thanks.

If they don't have a router as a gateway, you may be SOL. However, if they do, all you need is an access port, with an IP in their range, and to turn up their same routing protocol, or statics on both sides for the destination networks. That way their networks will know about yours (either via advertising or the statics), and yours will know about their's.

I'd have to think they have a router, as they have more than one network from your comments, unless of course each network is completely separated from the rest.

As for NAT, you can do the same thing as above, which is get an address in their range, and NAT all of your traffic through that address. Anything on their side will look like its coming from that one address, and the NATing router should take care of the rest when the reply traffic comes back.

All in all, I would recommend option A as long as there is not addressing overlap, but you will have no choice if there is.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required