Replacing Netscreen 5XP with Cisco 515E
Posted on 2004-11-07
Hi, I am replacing a Netscreen 5XP firewall with Cisco 515E. The netscreen has been working properly for the past 3 years and it is still functioning well but I need more robust device. I setup the Cisco and tested it by attaching two laptops, one to the interface 0 and the second to interface 1. They worked properly and I was able to access services "inside". I also called Cisco and had them verify the configuration as I am installing that firewall into the production env. They confirmed that everything was perfect.
After I installed the firewall by replacing them, I have run into problems. When I unplog the netscreen and plug in the cisco box, I am able to browse internally but people outside are unable to access any of the services such as www, https, VPN or 3389. Again I called Cisco and they went over the configuration just to confirm that it is perfect. They suggested that I am having problems because of the ARP table on the router before the firewall. The router is provided by the datacenter so I don't have access to it and Ican get it cleared. Is there only one router that I would normally have to have them clear?I want to see if you have any suggestions.
Appreciate all help.