Router to firewall network setup

Hello Experts,

    I am currently working on configuring a network diagram that will be ISP1/ISP2--->2621---->PIX 506E---->2912.  I want to run NAT and terminate vpn clients on the pix.  I have 2FE and 1 NM-1E on the 2621 to allow ISP1 and ISP2 (ADSL) connections to the 2621.  Reason being is I want to have some sort of failover/load balancing if possible.  

My confusion point right now is the ip addressing on the 2621.  
If I have static IP's from both ISP's and I'm going to nat on the PIX what would my IP's be on the 2621 internal interface and pix external interface?  I am assuming on the 2621 there will need to be static routes from the external interfaces to the internal interface.
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

  As I see it, you can do this in one of two ways. You can build both sets of IPs on the external and internal interfaces of the 2621 and the external interface(s) of the PIX. Then build NAT maps for both sets of IPs. Swapping the routing from one ISP to the other will probably be a manual process but you might be able to configure something dynamic in the PIX.
   The other way is the professional, but much more complex, solution. Get IPs from ISP1 and run BGP on the 2621. ISP1 gives you the IPs, they will already have them routed to you. With a BGP session to ISP2 (and permission from ISP1) they can route ISP1's IPs to you as well if the other circuit goes down. If neither ISP will give you permission to route their IPs through another ISP then you can try getting your own AS and IP space. Then you'll need BGP sessions to both.
   The first solution is way easier but the second doesn't require any manual intervention for fail-over.
Since both feeds are DSL, you have no option to use the "right" solution of BGP.
Since both feeds are Ethernet, you don't really need another router.
However, since the PIX can only have one default route out, you need the router to cosolidate paths

Having said that, I'm a big fan of Cisco and PIX, but in this case they don't make the right product unless you look at the Linksys division and their RV0x series. You might want to check out the RV016 product that would replace all three of your devices. No 2600, no PIX, no 2912 switch.
Automagic load-balancing/failover between the two DSL feeds and a fair SPI firewall and 10/100 switch all put together.

Another alternative is the Adtran Netvanta 1500 series all in one switch/router/firewall which also does load balancing over two (or more) Ethernet feeds

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
itwanlanAuthor Commented:
Thank You both for excellent answers.  I have been doing some heavy research on this all morning and would love to be able to use the cisco equipment if at all possible.  Is it at all possible to use floating static routes with different administrative distance for each ISP?  So if main ISP goes down it will route all packets out of the other ISP link.  There will be no services running behind this setup such as web server or anything else that will need BGP.  If this is a possibilty how would the pix know about a different default gw if the main ISP goes down.  

I know this is an extension of the main question so I will raise the points.

Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

Not that I am suggesting BGP for this application at all but why do you think you can't use BGP with DSL?
>If this is a possibilty how would the pix know about a different default gw if the main ISP goes down.  
It won't matter because the PIX will always send default traffic to the router.

>Is it at all possible to use floating static routes with different administrative distance for each ISP?
Yes, but you have to double-nat so that you nat outbound traffic to the 2nd ISP because you would assign the first ISP's public IP to the outside of the PIX.

Issues are that since the dsl modem is handing you off Ethernet, you have no way to know if the dsl side is down or not. There would be no interface event to change the routes to the backup link. You have to resort to other methods that complicate the scenario even further.
Then you have inbound services like www or email to worry about with 2 different possible public IP addresses.

>why do you think you can't use BGP with DSL?
DSL is designed as a commodity/soho provider and I've never yet seen a DSL provider that would play BGP with a customer unless it was a high-bandwidth business-grade circuit and even then they only wanted to use static defaults.

itwanlanAuthor Commented:
Thank You for clearing those questions lrmoore.

Thank You Both for you answers.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.