mhamzahkhan
n00b
- Joined
- Feb 19, 2010
- Messages
- 23
Hey everyone,
I joined a small company which requires a small cluster to be setup in the customers network.
So far, looking at the setup, I really don't like it. It is a mess.
So far, we only have two customers who require a cluster to be setup locally, everyone else uses the one hosted in our DC, but this number will be increasing very rapidly.
So the problem I'm having is deciding what the best way would be to have routed connectivity to the remote clusters.
Right now, the previous admin has done some crazy stuff.
So for example, we have a cluster in Turkey and Australia, each one has a VPN connection to the office, provided by two separate Cisco ASA 5505s.
Those ASAs are connected directly into our office network, so:
1) they have full access to our office network (no surprise here, the week I joined, I noticed that there were A LOT of people having fun on our primary samba fileserver... which was also our the office gateway with no firewall!)
2) both customers could really quite easily route packets into each others networks (but I'm guessing and hoping the remote sysadmin MUST have put some sort of firewalling in place...).
Naturally I want to stop both of these, so I figured one way I could do this is to have a separate VLAN for each customer, and have a Linux based router/firewall which routes packets from the office network to the required VLAN, but stops access from VLAN to each other.
But I don't think this is a good way since then if we have for example 30 locations, I would be dealing with 30 VLAN interfaces on the Linux router, and dealing with quite a lot of firewall rules, and also I will have a problem with IP addressing. Most of the clients will be using private ranges, making sure that a new customer doesn't select a subnet for the VPN/Cluster that we have already used for a previous customer would be impossible.
I was hoping to retain routed access to the remote network, rather than having to result in, for example, NAT or setting up an "access" box.
So I was wondering if any of you guys had any suggestions?
How do you guys deal with having connectivity to a cluster hosted on a customers network?
I joined a small company which requires a small cluster to be setup in the customers network.
So far, looking at the setup, I really don't like it. It is a mess.
So far, we only have two customers who require a cluster to be setup locally, everyone else uses the one hosted in our DC, but this number will be increasing very rapidly.
So the problem I'm having is deciding what the best way would be to have routed connectivity to the remote clusters.
Right now, the previous admin has done some crazy stuff.
So for example, we have a cluster in Turkey and Australia, each one has a VPN connection to the office, provided by two separate Cisco ASA 5505s.
Those ASAs are connected directly into our office network, so:
1) they have full access to our office network (no surprise here, the week I joined, I noticed that there were A LOT of people having fun on our primary samba fileserver... which was also our the office gateway with no firewall!)
2) both customers could really quite easily route packets into each others networks (but I'm guessing and hoping the remote sysadmin MUST have put some sort of firewalling in place...).
Naturally I want to stop both of these, so I figured one way I could do this is to have a separate VLAN for each customer, and have a Linux based router/firewall which routes packets from the office network to the required VLAN, but stops access from VLAN to each other.
But I don't think this is a good way since then if we have for example 30 locations, I would be dealing with 30 VLAN interfaces on the Linux router, and dealing with quite a lot of firewall rules, and also I will have a problem with IP addressing. Most of the clients will be using private ranges, making sure that a new customer doesn't select a subnet for the VPN/Cluster that we have already used for a previous customer would be impossible.
I was hoping to retain routed access to the remote network, rather than having to result in, for example, NAT or setting up an "access" box.
So I was wondering if any of you guys had any suggestions?
How do you guys deal with having connectivity to a cluster hosted on a customers network?