ScreenOS Firewalls (NOT SRX)
Reply
Visitor
Cameron1
Posts: 6
Registered: ‎01-13-2010
0

How to Extend LAN over VPN?

[ Edited ]

Is it possible to extend a LAN across a VPN?

 

Thank You!

Cameron

Juniper Employee
Juniper Employee
rvi
Posts: 16
Registered: ‎04-02-2009
0

Re: How to Extend LAN over VPN?

do you mean at layer 2/datalink...site to site vpns can extend over layer 3 networks

Visitor
Cameron1
Posts: 6
Registered: ‎01-13-2010
0

Re: How to Extend LAN over VPN?

 

1.) VLAN/Subnet (extend the same IP subnet across two distinct sides of a VPN tunnel, (for instance 192.168.1.0/24 exists at both sides of the VPN.)  I have not seen a solution for this functionality.

 

2.) DHCP or BOOTP across VPN.  That is possible using a ip helper or DHCP forwarder.  Works perfectly.

 

3.) Multicast.  Netscreen does not support Dense mode, which makes my multicast needs very unrealistic over a VPN Tunnel.  It is possible to use PIM - Protocol Independant Multicast across the VPN, but specific Multicast Routes and specific Mulitcast Policies are required, making it next to impossible for my configuration. 

 

Distinguished Expert
firewall72
Posts: 825
Registered: ‎05-04-2008
0

Re: How to Extend LAN over VPN?

Hi,

 

Yes, you can using NAT to address overlapping subnets over a VPN.  The C&E guide has a few examples.

 

-John

John Judge
JNCIS-SEC, JNCIS-ENT,

If this solves your problem, please mark this post as "Accepted Solution". Kudos are appreciated.
Distinguished Expert
echidov
Posts: 858
Registered: ‎11-02-2009
0

Re: How to Extend LAN over VPN?

Hi,

 

I do recommend to change addressing, otherwise you get a permanent source of problems and lose the overview (f.e. where is the DHCP-assigned 192.168.1.x now?). Besides, the arp-q's and arp-r's cannot be transported over the VPN.

 

Using NAT, as recommended by John, will help you to make a clean migration. And you can still use ip helper and DHCP forwarder.

 

You do not need PIM to transport multicast between two SSGs over  VPN. IGMP Proxy functionality is very good documented in the C&E (Routing). Tunnel interfaces can function as IGMP Proxies, both in Host and Router mode. But you need a Multicast policy that enables IGMP transport over VPN.

 

Kind regards,

Edouard

Kind regards,
Edouard
Contributor
joekim1113
Posts: 45
Registered: ‎08-07-2008
0

Re: How to Extend LAN over VPN?

[ Edited ]

Have you looked into VPLS? (can't do w/ screenos)

JNCIS-ES
JNCIS-FWV
JNCIA-WX
JNCIA-SSL
JNCIA-UAC;
JNCIA-EX
JNCIA-IDP
Juniper Elite Partner Enterprise Solutions Provider & Service Provider Infrastructure
Operate & Implement Specialist
www.novadatacom.com

Hit the Kudos button if my info helps. :smileyhappy:
and if this worked for you please flag my post as an "Accepted Solution" so others can benefit.
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.