General discussion
-
Topic
-
LAN to LAN connection
LockedScenario –
LAN A has it’s own T1 line with a Cisco PIX 515E (3 interfaces) firewall. Inside, Outside, and DMZ are the names of the zones. Inside consists of local PC’s and internal servers. DMZ has webservers. The default gateway for client PC’s is pointed to the firewall.
LAN B is the same except for the IP scheme and some local resources. IIS and MS Exchange exist in the DMZ where as the local PC’s are in the inside zone.
The goal is to have LAN A and LAN B access certain resources from each other without using the internet. For example Users on LAN A will need access to MS Exchange on LAN B. Both LAN’s exist in the same building and all the networking equipment will exist in the same room. The goal is to also open/close ports as needed between the 2 networks. Also, each network will have to use their own T1 connection for web browsing and such.
My proposed idea is to have a firewall (2 interface) that sits between LAN A’s inside network and LAN B’s inside network. One interface will physically connect to LAN A’s switch and the other interface will connect to LAN B’s switch. I’m not sure if this is the best way to do this or it will give me all of the desired results. If does seem like the most practical solution….do I need to add static routes to the Cisco PIX on LAN A and LAN B? Typically this scenario would be more like a WAN with a leased line connection between the sites. Would I need to have a router for each LAN?
Thanks