?
Solved

adding a secondary IP to same interface on a Cisco ASA 5510

Posted on 2007-12-03
9
Medium Priority
?
7,241 Views
Last Modified: 2010-11-04
My ISP gave me another block of IPs to use on the same interface. I know I can just add a secondary IP to the interface but what else do I have to do with the second gateway? Right now I just have a "route outside 0.0.0.0 0.0.0.0 y.y.y.y"   command in the config. What else do I have to do to accomplish this 2nd block of IPs?
0
Comment
Question by:fina27
  • 4
  • 2
  • 2
  • +1
9 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 2000 total points
ID: 20399358
>>"I know I can just add a secondary IP to the interface"

On an ASA, you cannot add a secondary IP address to an interface...are you talking about adding subinterfaces to be used in a VLAN environment, perhaps?

Truthfully, if your ISP has given you a new block of addresses that you want to be able to use, it's really just as simple as configuring static translations for the new block of IP addresses to point to internal IP addresses.  The ASA will perform proxy ARP for the new IP's.  You shouldn't even have to use the second gateway for the new block at all since you're routing would be taken care of by your existing default route.  As long as your ISP is taking care of routing the new block to your connection with them, then you should be OK and not have to specify the second gateway.
0
 

Author Comment

by:fina27
ID: 20399443
Yeah as I was thinking about it more i figured that would be the case about the gateway.

So how can I configure this additional IP block? I just need a little more insight on how to implement it. I can't do a "ip address ip-address mask secondary" command on the interface?


"it's really just as simple as configuring static translations for the new block of IP addresses to point to internal IP addresses." ---- so if I just start doing "static (inside,outside) 'new WAN IP' LAN IP netmask mask"    It will work?
0
 
LVL 28

Expert Comment

by:batry_boy
ID: 20399660
>>I can't do a "ip address ip-address mask secondary" command on the interface?

No, it doesn't support the "secondary" option in the ASA code.

>>so if I just start doing "static (inside,outside) 'new WAN IP' LAN IP netmask mask"    It will work?

As long as your ISP has done their part in routing that new net block to your edge router or device, then yes it will work.
0
Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

 

Author Comment

by:fina27
ID: 20400341
That didn't work. Should I create a sub-interface?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 20400459
All you have to do is create static 1-1 nat xlates to the new ip range. Done.
0
 

Author Comment

by:fina27
ID: 20400714
can you give me that command?
0
 

Author Comment

by:fina27
ID: 20400796
static (inside,outside) y.y.y.y x.x.x.x netmask mask

y=wan
x=lan


I entered that command and tried to ping it and still cannot. Is there something else?
0
 
LVL 13

Expert Comment

by:td_miles
ID: 20401630
you need to permit the traffic through the interface for the NAT to work.

something like:

access-list 101 permit tcp any host y.y.y.y eq 80
acess-group 101 in interface outside

which would allow traffic to a web server on IP y.y.y.y
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 20402666
You also cannot ping it from inside.
You also need to make sure that your ISP is routing that block of IP's to your PIX's current outside interface IP
0

Featured Post

Prepare for an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program curriculum features two internationally recognized certifications from the EC-Council at no additional time or cost.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
As managed cloud service providers, we often get asked to intervene when cloud deployments go awry. Attracted by apparent ease-of-use, flexibility and low computing costs, companies quickly adopt leading public cloud platforms such as Amazon Web Ser…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month17 days, 10 hours left to enroll

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question