← Back to list
middle
Registration: 29.04.2022

Vitaly Volkov

Specialization: Networks

Portfolio

Cisco CSR as VPN Hub

Configure Crsco CSR 1000 and make it a hub fot IPSec Site-to-Syte VPNs and L1TP VPN netwrork

Network topology

The tasks were to replace an old and outdated Nortel Passport 8606 router in the core of a network with new Juniper SRX650 routers, and to move a function of a core router from Cisco ASA to SRX650. Two SRX650 devices were deployed in cluster mode with load distribution between two nodes. Two Cisco ASAs in Standby Failover mode were placed on the network edge and served as primary firewall and VPN termination point.

VPN topology

The project goal is to securely connect together servers in the office on-premise, in two data centers and in AWS. On each endpoint the IPSec VPN service is configured and tunnels to other locations established. strongSwan, an IPSec VPN suite for Linux, is installed on DC servers directly, while on the AWS, a dedicated VPN server is deployed. AWS routing is modified to make this server as an Internet gateway for the whole AWS infrastructure, including Lambda functions integrated with AWS VPC. Ubiquiti EdgeRouter terminates the VPNs on the on-premise side.

Skills

Cisco
Cloud networking
VPNs

Work experience

Network Engineer
since 05.2016 - Till the present day |Filuet RS

Educational background

Computer Science (Bachelor’s Degree)
1998 - 2003
Russian University of Transport (MIIT)

Languages

EnglishProficientFrenchUpper Intermediate