Tunnels show up again.

That was the first line of the update I sent Peek today.

The firewall now shows both secure connections up. They are only the IKE tunnels. T-Mobile still has to update the GRE endpoints before we can run ping tests across the whole path.

So this is progress, not finished.

The integration has followed me out of Peek. I left for Reality Check in March, but told the team I was available to help get it working. The original network used the same segment for two different tunnel endpoints. Changing the equipment brand would not fix that. The IP assignments had to change.

I wrote the reason plainly a couple of weeks ago:

I'd really like to help you guys out here and play some sort of role, I really believed in Peek and was sad to be leaving it behind.

We had also discussed a larger hosting arrangement. It did not work for me without a second ISP in the data center. My customers want BGP, and the cost of adding the missing circuit did not make sense compared with leasing space somewhere that already had it.

I offered a much smaller support retainer instead: finish the network, manage it, and be available when something breaks.

Today the firewall finally showed both tunnels again.

I also asked a very senior friend at Juniper about the high-availability design. His answer was wonderfully short:

It works.

The secure connections are up.

Now the carrier has to move its endpoint so we can see whether the traffic works too.

Archive