Solved

Network Design Question

Posted on 2007-11-16
2
230 Views
Last Modified: 2010-04-17
Right now a pix firewall is the edge device. It connects directly to the ISP's router. I am going to use BGP with an additional edge router to multihome 2 isp's. What is the best configuration as far as routing protocols?

The Pix can use Rip or OSPF. Should I use a protocol or just static routes on the pix? Is it possible to run BGP on the edge router and have the Pix outside int connected to a switch with the router on the switch too? This is because there is another failover pix, so i assume there needs to be a switch in between the router and the pix.

On the inside of the pix there is a L3 switch doing internal routing. It is using EIGRP.

What is the best way to design this?
0
Comment
Question by:jaysonfranklin
2 Comments
 
LVL 28

Accepted Solution

by:
Jan Springer earned 500 total points
ID: 20301472
ISP A/ISP B (BGP) -> your router (BGP)
your router (static routes) -> pix

Make sure that you have a static route to null0 with a weight of 250 for the networks that you will be advertising via BGP.  That way if the ethernet or switch goes down or the pix does not failover, your routes will not be withdrawn.

you are correct that you need a switch to connect the two firewalls and a router for failover to the inside network.
0
 
LVL 1

Author Comment

by:jaysonfranklin
ID: 20314091
Ok, thanks...
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question