Solved

Using a single interface router as a gateway

Posted on 2004-09-17
2
549 Views
Last Modified: 2012-06-21
Has anyone ever used a single interface router as a gateway before?  In other words, a router with only one Ethernet interface and all traffic enters and exits the same interface.  I worked at a large international company that had a DMZ with over 100 web servers in it.  The gateway routers only had one interface and were setup in an HSRP fashion.  The DMZ servers pointed to the HSRP address for their gateway.  The router then routed all traffic to an interface on the firewall.  I’m building a DMZ for the company I work for now and I’m considering the same setup but I want to know if anybody has used this configuration and would recommend it.  Would this work the same as using a router with two Ethernet interfaces?  It worked very well at the other company I worked for.  I’m curious what everyone thinks of this setup.  Below is a snippet of a possible config that I could use.

Router with only one interface:

interface FastEthernet0/0
 ip address 10.10.1.2 255.255.255.0
 no ip redirects
speed 100
 full-duplex
 standby 10 ip 10.10.1.1
 standby 10 priority 200
!
no ip http server
no ip http secure-server
ip classless
ip route 0.0.0.0 0.0.0.0 10.10.1.4     (IP of interface on firewall)

Cisco 2620’s are cheaper then the 2621 so that’s why I’m considering this setup.  Anyone have any good/bad opinions on this.

Thanks
0
Comment
Question by:steno1122
2 Comments
 
LVL 11

Accepted Solution

by:
PennGwyn earned 20 total points
ID: 12089356
I don't see what role HSRP plays here.

About the only issue with this kind of setup is to remember to turn off redirects, as you have done.


0
 

Author Comment

by:steno1122
ID: 12089406
HSRP is used for gateway redundancy.  If I only had one router and it went down then traffic won't be routed to the firewall.  The gateway IP for the DMZ servers will be the HSRP address.  That way if there is a hardware failure traffic will still be routed to the PIX.

Thanks for your reply PennGwyn.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Port Forwarding on Cisco 881 14 70
EIGRP STUB 19 99
How to Link NetGear wireless AC-1200 router to Sonicwall 3600 13 72
Provide internet access from one windows PC to another 16 101
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question