Cisco Split DNS

From: patch29 Jul 2013 21:32
To: Ken (SHIELDSIT) 9 of 29
Yes.
From: patch29 Jul 2013 21:33
To: patch 10 of 29
The really fun bit is when you realise that the same subnet is used on both sides of the tunnel. Then you have to start NATing stuff.
From: Ken (SHIELDSIT)29 Jul 2013 22:28
To: patch 11 of 29
Yeah, we are good that way.  All our sites are all already connected, I'd just like to get them using local internet.
From: Serg (NUKKLEAR)29 Jul 2013 22:43
To: Ken (SHIELDSIT) 12 of 29
Yes, I think it should work... do you have different subnets at each site?
From: Ken (SHIELDSIT)30 Jul 2013 08:10
To: Serg (NUKKLEAR) 13 of 29
I sure do!  I didn't get very far with it yesterday because I was lazy, I'll see what I can accomplish today.
From: Serg (NUKKLEAR)30 Jul 2013 09:12
To: Ken (SHIELDSIT) 14 of 29
Alrighty, let us know if you need a hand.

Edit: just had a thought about DNS, do you have a DNS server at each site? If not, you'd have to set your main DNS server as the first, which would add a tiny bit of network load and potential delay in name resolution if the VPN goes down.
EDITED: 30 Jul 2013 09:14 by NUKKLEAR
From: Ken (SHIELDSIT)30 Jul 2013 09:20
To: Serg (NUKKLEAR) 15 of 29
aye I do, each site has a dc to aid in log ons, do dhcp and dns.
From: Ken (SHIELDSIT)18 Sep 2013 17:02
To: Dan (HERMAND) 16 of 29
No idea if I've answered your last question or not.  At our remote locations I have 870's and here at the main office I replaced the 870 with a RV042G.

If I attached my config could someone help me split it?
From: Ken (SHIELDSIT)18 Sep 2013 17:04
To: Serg (NUKKLEAR) 17 of 29
I do need a hand. If I post my config dump could you try to help me figure out how to set up the split DNS?
From: Serg (NUKKLEAR)19 Sep 2013 10:50
To: Ken (SHIELDSIT) 18 of 29
I'd say don't post it on a public website.. but yeah, happy to help  ;-)
From: Ken (SHIELDSIT)19 Sep 2013 11:58
To: Serg (NUKKLEAR) 19 of 29
I could sanitize it, or I can upload it to dropbox and share it with you?  thanks a bunch for the time and help!
From: patch19 Sep 2013 12:27
To: Ken (SHIELDSIT) 20 of 29
Sanitise it. Then I can have a look too.
From: Ken (SHIELDSIT)19 Sep 2013 12:36
To: patch 21 of 29
Will do!  Thanks!
From: Ken (SHIELDSIT)19 Sep 2013 12:48
To: Serg (NUKKLEAR) patch 22 of 29
Ok here it is. I think I removed anything that could be of any interest.

The remote locations are 870's.  This is pretty much the config that's been on them since whoever set them up did it.
From: Ken (SHIELDSIT)27 Sep 2013 13:45
To: ALL23 of 29
Do any of you know if it's possible to make an Eth port a WAN port?  I can do it with my router at home but it doesn't speak Chinese like this one.  If I can get dual WAN on this router I will take the RV042 out of service, I don't think it's a very good router.  I've attached a pic of the router.  It's an 870. 
Attachments:
From: Dan (HERMAND)27 Sep 2013 16:32
To: Ken (SHIELDSIT) 24 of 29
Probably not with something like that. The 4 ports will be a simple Layer 2 switch with no routing capability, meaning they'll all have to be on the same subnet.
From: Ken (SHIELDSIT)27 Sep 2013 18:21
To: Dan (HERMAND) 25 of 29
So I wonder how I can do it on my Asus?
From: Dan (HERMAND)27 Sep 2013 19:15
To: Ken (SHIELDSIT) 26 of 29
What's the Asus model? I'd guess it's a Layer 3 switch inside meaning it has the capability.
From: Ken (SHIELDSIT)27 Sep 2013 19:17
To: Dan (HERMAND) 27 of 29
From: Dan (HERMAND)27 Sep 2013 19:25
To: Ken (SHIELDSIT) 28 of 29
Yeah, looks like that got Dual-WAN capability with a firmware update. 

I did find this for your Cisco:

http://www.gossamer-threads.com/lists/cisco/nsp/107630