corsasport.co.uk
 

Corsa Sport » Message Board » Off Day » Geek Day » Leased Line and IP Addresses


New Topic

New Poll
  Subscribe | Add to Favourites

You are not logged in and may not post or reply to messages. Please log in or create a new account or mail us about fixing an existing one - register@corsasport.co.uk

There are also many more features available when you are logged in such as private messages, buddy list, location services, post search and more.


Author Leased Line and IP Addresses
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
24th Sep 14 at 08:34   View User's Profile U2U Member Reply With Quote

We are looking to install a leased line at our head office and are being asked how many IP addresses we'd like and our proposed intentions, i.e

1x VPN
1x Exchange
1x File Server
etc

What benefit does splitting the traffic carry? As they are all coming down the same pipe, I cant imagine theres any speed improvements? Is it just a way of keeping things neat and tidy?

Also, how Is it likely to be processed at the office end, i.e will the router forward this traffic to the right server etc?
VrsTurbo
Premium Member

Registered: 8th Jun 10
User status: Offline
24th Sep 14 at 10:26   View Garage View User's Profile U2U Member Reply With Quote

Neat and tidy. I have all my Enterprise VPN's down one IP, Exchange on another, Externally facing devices on another etc etc.

Just makes the firewall easier to manage and can see the traffic on each IP a lot better.

You'll still need a firewall to manage it all, unless you give the provider your internal IP's and they do the mapping which seems odd.

[Edited on 24-09-2014 by VrsTurbo]
Dom
Member

Registered: 13th Sep 03
User status: Offline
24th Sep 14 at 10:40   View User's Profile U2U Member Reply With Quote

I've always dumped Exchange on it's own IP and everything else on another or if i've got spare IP's then i split services across them like VRS mentions.
And you're router/firewall would do the IP/address mapping from WAN to internal addresses.

I wouldn't have thought you'd need to make your file server externally facing though, not when remote users will have VPN access

[Edited on 24-09-2014 by Dom]
VrsTurbo
Premium Member

Registered: 8th Jun 10
User status: Offline
24th Sep 14 at 10:46   View Garage View User's Profile U2U Member Reply With Quote

File server maybe external due to Direct Access, but then again thats not needed if using a vpn.
pow
Premium Member

Avatar

Registered: 11th Sep 06
Location: Hazlemere, Buckinghamshire
User status: Offline
24th Sep 14 at 10:47   View Garage View User's Profile U2U Member Reply With Quote

Exchange on one, DirectAccess on another, website services on another.
John
Member

Registered: 30th Jun 03
User status: Offline
24th Sep 14 at 11:19   View User's Profile U2U Member Reply With Quote

For small business/couple of server type setups I just use 1. Anything with multiple ports going to multiple servers, I split it up.
willay
Moderator
Organiser: South East, National Events
Premium Member


Avatar

Registered: 10th Nov 02
Location: Roydon, Essex
User status: Offline
24th Sep 14 at 11:33   View Garage View User's Profile U2U Member Reply With Quote

Some services should have their own IP address, VPN and Mail server being a good example. Other services such as a bunch of websites hosted on different domains can use the same IP.

Try and get a nice allocation of IP addreses with your line (8 or 16 IPs), they may ask you to fill out a RIPE form to justify your allocation, you can generally fill this with bollocks and get some IPs.
Neo
Member

Registered: 20th Feb 07
Location: Essex
User status: Offline
24th Sep 14 at 13:14   View User's Profile U2U Member Reply With Quote

quote:
Originally posted by willay
they may ask you to fill out a RIPE form to justify your allocation, you can generally fill this with bollocks and get some IPs.


This, I usually add stuff like WANVPN, IPSEC VPN, Bespoke application 1, MGMT to make up the numbers.

Kyle T
Premium Member

Avatar

Registered: 11th Sep 04
Location: Selby, North Yorkshire
User status: Offline
24th Sep 14 at 13:34   View Garage View User's Profile U2U Member Reply With Quote

I'm doing a bunch of small office/production facility type deployments here in the US and we've been requesting /29 networks with 6 host addresses:

DGW of the ISP
VPN Endpoint for Clients
VPN Endpoint for tunnels to other sites
SIP Trunk endpoint for VOIP
<2 spares, one of which will be a video conference suite at the main office>

They're using Exchange Online so that's not a consideration, and they aren't hosting anything for public consumption.


Lotus Elise 111R

Impreza WRX STi
willay
Moderator
Organiser: South East, National Events
Premium Member


Avatar

Registered: 10th Nov 02
Location: Roydon, Essex
User status: Offline
24th Sep 14 at 14:08   View Garage View User's Profile U2U Member Reply With Quote

a separate IP for VPN Clients and VPN tunnels? are they separate devices or something?
pow
Premium Member

Avatar

Registered: 11th Sep 06
Location: Hazlemere, Buckinghamshire
User status: Offline
24th Sep 14 at 14:09   View Garage View User's Profile U2U Member Reply With Quote

Yeah that form is bollocks, just fill it in as suggested to get more than you need.
Dom
Member

Registered: 13th Sep 03
User status: Offline
24th Sep 14 at 14:31   View User's Profile U2U Member Reply With Quote

quote:
Originally posted by willay
a separate IP for VPN Clients and VPN tunnels? are they separate devices or something?


Site-to-Site tunnels i imagine; can't say i've used a dedicated address for that, usually i just bung it with other services.


Having seen some installations, some folk do take the absolute piss with the number of addresses they request; it's no wonder we're running out of IPv4

Speaking of which, and a slight de-rail, has anyone made the transition to IPv6 (or at least run/use it to some extent on their networks)?
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
24th Sep 14 at 15:35   View User's Profile U2U Member Reply With Quote

Managed to get 10 IP addresses in total.
Just made up a load of stuff mentioning services we don't have and they've just agreed to it, so happy with that.
Kyle T
Premium Member

Avatar

Registered: 11th Sep 04
Location: Selby, North Yorkshire
User status: Offline
24th Sep 14 at 18:53   View Garage View User's Profile U2U Member Reply With Quote

Separate devices Willay. Cisco doing the tunnels, checkpoint doing the clients... It's the nature of the way we phased the deployments.


Lotus Elise 111R

Impreza WRX STi

 
New Topic

New Poll

  Related Threads Author Forum Replies Views Last Post
pics of my car final got it bk beattie17 General Chat 41 1365
3rd Jul 03 at 18:19
by beattie17
 
I just found out that Japan have... Martyn Geek Day 9 1472
24th Nov 03 at 12:37
by Dan B
 
Anyone know anything about this please Kerry Geek Day 42 3804
30th Apr 04 at 22:37
by Andy
 
PHat download speeds with a capital PH... Cybermonkey Geek Day 31 1950
2nd Nov 04 at 03:51
by Cybermonkey
 
Post your broadband speeds from speedtest.net Sam Geek Day 79 2013
28th Oct 08 at 13:39
by Dan Lewis
 

Corsa Sport » Message Board » Off Day » Geek Day » Leased Line and IP Addresses 29 database queries in 0.0144460 seconds