Re: Two Gateways On Same Subnet



There is no easy way around that sort of problem. It usually involves a
reconfig of the network. Normally the remotes would connect to your edge
firewall which would be the default route for the LAN machines. The WAN
links are not a problem because you know what address range they use. You
can redirect their traffic pretty easily. But single remote users are a
problem.

Another way to solve remote access problems is to have the remote access
device "inside" the firewall/Internet gateway. You can then route the
traffic destined for a remote user (based on its private IP range which you
do know) to the remote access server. After it is processed (ie encrypted
and encapsulated) it continues to the Internet gateway device.

I can't really see why your LAN machines (other than the servers you
mention) are not also using the firewall as their default gateway. Does
sending all traffic through this device overload it?

A default route is used when no other route is defined for the target
address. The default route has to point to your default gateway. There can
only be one of those. Normally both Internet access from the LAN and remote
access to the LAN require the use of a default route (because there is no
way you can know what the public IP address is going to be). There isn't any
way that you can decide what should go where based on its destination
address.

What device do your remote clients connect to? A Cisco might be able to
decide on one gateway rather than another based on the source address of the
incoming traffic from your remote clients. Windows can't.



Net Admin wrote:
Looking for some advice. I have a Qwest PRN WAN connecting all of
our field offices to our corporate office, using Cisco 1800 routers
and then our main firewall is a Cisco ASA 5510. Our Qwest gateway is
192.168.2.1 and our firewall is 192.168.2.50. Our Exchange server
and three other main Windows Server 2003 file servers that everybody
outside of the corporate use have the 192.168.2.50 set as their
gateway on the NICs. This is so remote users outside of the WAN have
no connectivity issues. All other computers use the 192.168.2.1 for
their gateway through Qwest. We are having connection issues where
anybody using 192.168.2.1 as their gateway cannot see any computers
using the 192.168.2.50 as their gateway. My question is, how can you
make both gateways see each other so that every computer can see one
another? Is it something that can be done through Windows? I have
already tried different methods of routing within the Cisco equipment
but are unsuccessful. A Cisco engineer working for Cisco also saw
that no ip routes or gateway masking can be used. Any ideas how
these two gateways can point traffic at each other?

Any advice or ideas would greatly be appreciated. Thank you.


.



Relevant Pages

  • Re: VPN and remote gateway
    ... 317025, we could know that if you use local gateway, your internet connection will not be a problem, but, you could not access your ... remote network since there is no route between you computer and your remote company network. ...
    (microsoft.public.windows.server.sbs)
  • Re: Config TCP Gateway
    ... wouldn't the supplier get assigned an IP address from ... If I understand you correctly that all remote traffic (your remote sites ... Pity you didn't list the requirements for the new gateway as well. ... just add a route specifying that network as the ...
    (comp.sys.ibm.as400.misc)
  • Re: VPN and remote gateway
    ... using the remote network as my gateway. ... I use the VPN connection that I set up manually that is setup to not use the ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Monitoring of embedded devices
    ... > be via CAN, RS232, and one day, even wireless, to the gateway. ... > For those who have such remote monitoring applications, ... > think a customer would always be willing to give you access to their ...
    (comp.arch.embedded)
  • Re: win2000as routing
    ... If you are trying to use this method to route between the two sites, ... You do not need to configure routing manually. ... the remote site dials in, it connects to the demand-dial interface and the ... Ethernet card IP address is 192.168.0.2 with default gateway on ...
    (microsoft.public.win2000.ras_routing)