[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [afnog] Oposite of VPN ?



On Fri, Aug 15, 2003 at 08:32:42PM +0000, Mohamadi ZONGO wrote:
> The diagram look like this :
> 
> INTERNET                     Intranet
>    /                         leased
>    /                         line
>    R1----+---- FW ----+----R2=========R3-----+-------+
>          /            /                      /       /
>          /           /                      /       / 
>         VPN1      TRUSTED NET1     TRUSTED NET2    VPN2---+--  
>                                                           /
>                                                           /
>    ^^^^^^^^^^                                      CYBERCAFE(UNTRUSTED)
>    UNTRUSTED

Absolutely. As long as VPN1 and VPN2 can 'see' each other's outside IP
address, i.e. FW policy permits the tunnel packets between VPN1 and VPN2,
and VPN2 routes *all* cybercafe traffic over the tunnel, this will be fine.
If someone in the cybercafe were to try to access the trusted net, they
would find themselves on the 'outside' of FW.

R1 will probably have a static route for the subnet you've allocated to the
cybercafe pointing at VPN1 (unless VPN1 participates in your IGP)

Regards,

Brian.
__________________________________________________
This is the Africa Network Operators' Group(AfNOG) 
technical discussion list.
The AfNOG website is: <http://www.afnog.org>