VPN to Customer Networks

Joined
Feb 19, 2010
Messages
23
Hey everyone,

I joined a small company which requires a small cluster to be setup in the customers network.

So far, looking at the setup, I really don't like it. It is a mess.

So far, we only have two customers who require a cluster to be setup locally, everyone else uses the one hosted in our DC, but this number will be increasing very rapidly.

So the problem I'm having is deciding what the best way would be to have routed connectivity to the remote clusters.

Right now, the previous admin has done some crazy stuff.

So for example, we have a cluster in Turkey and Australia, each one has a VPN connection to the office, provided by two separate Cisco ASA 5505s.

Those ASAs are connected directly into our office network, so:
1) they have full access to our office network (no surprise here, the week I joined, I noticed that there were A LOT of people having fun on our primary samba fileserver... which was also our the office gateway with no firewall!)
2) both customers could really quite easily route packets into each others networks (but I'm guessing and hoping the remote sysadmin MUST have put some sort of firewalling in place...).

Naturally I want to stop both of these, so I figured one way I could do this is to have a separate VLAN for each customer, and have a Linux based router/firewall which routes packets from the office network to the required VLAN, but stops access from VLAN to each other.

But I don't think this is a good way since then if we have for example 30 locations, I would be dealing with 30 VLAN interfaces on the Linux router, and dealing with quite a lot of firewall rules, and also I will have a problem with IP addressing. Most of the clients will be using private ranges, making sure that a new customer doesn't select a subnet for the VPN/Cluster that we have already used for a previous customer would be impossible.

I was hoping to retain routed access to the remote network, rather than having to result in, for example, NAT or setting up an "access" box.

So I was wondering if any of you guys had any suggestions?
How do you guys deal with having connectivity to a cluster hosted on a customers network?
 
What is the connectivity for? For support when they call or does the software access your company's servers or what? Do you need a 24/7 VPN connection or just sometimes?
 
We have a multiple subnetted VPN backend across all our datacenters using VPN devices at each location.

Here's a hint: there's no linux server, and there's no Cisco AS anything.

Sounds like the previous admin is "previous" for a reason. Don't fuck up like he did.
 
why not just put rules into the ASAs on their end to stop them having access to the network?
 
I'd do the following:

1) Give each one a vpn.
2) Give a block in by default rule from their network to yours EXCEPT exactly what they need access to.
 
why not just put rules into the ASAs on their end to stop them having access to the network?

just go put an ACL on their asa that blocks all traffic to your network from theirs. Just leave holes for you to be able to do things and remove that ACL if needed.
 
Er no, if you actully want to setup a secure system, you don't put rules on the box they have physical access to.

Any security must be done on your side of the network, which you control.

The ASA is a fine solution, I'm sure there are others. You can use NAT as part of the VPN connection, so even if the customers' have colliding IP address schemes, you'll still be able to connect properly.

You can do that with an ASA at their end, and a single ASA at your end (for all customers).
 
Just put ACLs on the ASA in your DC to grant access to only the specific host on specific ports/services they need. Then add a Deny everything else ACL.
Be done.
 
What is the connectivity for? For support when they call or does the software access your company's servers or what? Do you need a 24/7 VPN connection or just sometimes?

Well, it needs to be up 24/7. It's used for support, maintenance, monitoring, and there is a lot of data that is transferred between our local servers and the remote clusters.

We have a multiple subnetted VPN backend across all our datacenters using VPN devices at each location.

Here's a hint: there's no linux server, and there's no Cisco AS anything.

The problem isn't with the linux server or Cisco ASA really, I actually quite like the ASAs. >.>

The big problem I'm having is thinking of a way to subnet these VPN tunnels.

For example, with one customer might need to use a commonly used subnet, for example 192.168.1.0/24 for their cluster, then we will have an issue if another customer decides to use the same range.

Although we can say "not" to use that range in such a case, it will be a bit problematic finding a suitable range, that "fits" in with their current infrastructure if that makes sense?

Sounds like the previous admin is "previous" for a reason. Don't fuck up like he did.

Well they hired me, as the previous guy wasn't really a sysadmin. I'm not sure what his official title was, but the developers plus him were doing the system administration together, although he was doing most of it.

When I started here, he was still working here, but as soon as I discovered how badly he had screwed up, on so many things other than the fileserver/firewall, he decided to resign within the second week of me being here. >.>

My to-do list is frigging huge now. :p

Er no, if you actully want to setup a secure system, you don't put rules on the box they have physical access to.

Any security must be done on your side of the network, which you control.

The ASA is a fine solution, I'm sure there are others. You can use NAT as part of the VPN connection, so even if the customers' have colliding IP address schemes, you'll still be able to connect properly.

You can do that with an ASA at their end, and a single ASA at your end (for all customers).

The firewalling would be done on my end, not theirs. Often, I won't even have access to their VPN endpoint so it has to be done on my end. :/

Oh my god, I can't believe I didn't think of NAT!
One-to-One NAT would work beautifully! I can't believe this didn't come to my mind. I wouldn't even have to care what the customer uses anymore.

Would you guys recommend using a separate ASA device per customer?
This would mean having a lot of ASA devices. Just in the last two months, we've got 5 new clients, and I'm certain that they will come rolling in very very quickly.

I kind of like the idea of having a separate VPN endpoint per customer, but it wouldn't be space, or energy efficient would it?
 
Back
Top