Setup Metro ethernet (KPN EVPN)

Setup Metro ethernet (KPN EVPN)

NewsGroups | Search | Tools
 comp.dcom.lans.ethernet  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Setup Metro ethernet (KPN EVPN) Dennes 07-03-2007
Posted by Will on July 6, 2007, 3:05 am
If you were  Registered and logged in, you could reply and use other advanced thread options


> Hi,
> We have just replaced our existing DSL based VPN solution with a metro
> ethernet one, connecting our 3 sites together over 10Mbit links.
> Now i just have a simple question.
> The telco setup the metro ethernet (layer 2 multipoint ethernet
> connection between the 3 sites) and installed Nortel 1400 ESM switches
> at each site. After that, they were gone and could'nt tell me how to
> further configure it.
>
> If i'm right, i actually have an ethernet link between every site, but
> i cannot just plug the Nortels in the existing switches at each site
> since all sites are on a different subnet, right?

Forget router, I would put in a routing firewall. Whatever makes you
believe the telco's promise that they have you on a private virtual
ethernet? I know the Nortel OPTera 3500 product (which is probably what
they build their metro network around if they are using a Nortel solution)
well enough to know it would be extremely easy for them to put another
company's virtual ethernets overlapping yours, even if by accident. One
day in the future you might wake up finding that you have invited several
other companies directly onto your internal network, with direct routes onto
any of your hosts.


> So do i need an ethernet router at each site, connected between the
> Nortel (WAN) and the existing LAN and setup another new subnet for the
> "WAN net"? But what would i use as gateway at the wan ip side?

Did the ISP providing you the virtual ethernet also provide you an Internet
connection on the same virtual ethernet? I don't see how they could do
that unless they were providing an NAT router for you. I wouldn't feel
safe connecting to the Internet through another vendor's NAT alone.

Presumably they gave you some instructions about your Internet router? The
routing firewalls would route all Internet bound packets on a separate
subnet that is exposed outbound to the Internet. Internal traffic between
sites could go on a separate subnet connecting the various sites.
Personally I would place your internal networks at each site on separate
subnets of each routing firewall that are separate from the subnets that
interconnect sites, and use VPN and firewall routing rules to make sure
anything coming in from one of your other sites is probably authenticated.

--
Will



Similar ThreadsPosted
Metro Ethernet January 4, 2007, 7:19 pm
Looking for a good article on "Metro Ethernet" September 3, 2006, 1:33 pm
Best HA switch setup? August 29, 2006, 8:58 pm
Hardware/Software setup March 28, 2007, 3:07 pm
Netgear router setup problem January 7, 2006, 7:56 pm
Netgear router setup problem January 7, 2006, 7:56 pm
Simple (I think?) Managed Switch Setup August 15, 2006, 9:56 pm
USB Ethernet controllers that use the ASIX AX88772 or AX88172 USB-Ethernet bridge devices August 19, 2005, 4:04 pm
Difference between Ethernet 2 and 802.3 Frame per the Ethernet FAQ July 28, 2006, 9:02 am
ethernet hub April 27, 2006, 2:44 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map