Solved

ASA integration with LAN & WAN

Posted on 2008-10-20
14
489 Views
Last Modified: 2012-05-05
implementation solution required for integrating LAN with WAN.
2 4500s working as core+distribution switch. hsrp shall be implemnted in the core for access. both the switches shall be connected to 2 ASA5510 integrating LAN. WAN set up consisting of 2 2800s shall cater to Internet & MPLSWAN  connected to both the ASAs. (ASAs with security license are sandwiched betn LAN & WAN).

can you help me to come up with robust solution consideration for the above set up please.
0
Comment
Question by:nocss
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 7
14 Comments
 
LVL 32

Expert Comment

by:rsivanandan
ID: 23070972
What exactly are you looking for? Solution wise you already have it?

Cheers,
Rajesh
0
 

Author Comment

by:nocss
ID: 23313899
i have some doubts..
1. hsrp would be implemented for access switch rings. odd vlans primary for cs1 & even vlans primary for cs2. both the switches would be uplinked thru ASA5510. should both the FWs be configured in A/A or A/P mode for failover.
2. will hsrp tracking towards FW be reqd for better convergence.
3. could the etherswitch NM modules integrated with 2811 ISRs for consolidating layer2 links coming out of FWs and entering respective router interface.
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 23334872
1. It really doesn't matter much unless you have like more than 100Mbps of internet link. Say you put it in;

active/active -> The maximum throughput you get is only the maximum of your internet bandwidth, so pushing through both the boxes at the same time won't get anything increased for you.

active/passive -> Again same, your active one is more than enough to push the traffic.

2. It is recommended to use tracking for end to end.

3. I do not understand the question.

Cheers,
Rajesh
0
Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

 

Author Comment

by:nocss
ID: 23335293
1. agree. asa5510 comes with a/a default. so change the set up to a/p and run lan-based failover?

2. end to end set up would be "access swt --- core switch(collapsed core)---asa5510---ISR2811". i assume end to end for hsrp tracking would be between cs & fw or anything else?

3. there would be total 2 outside interface (one of each fw) which should be consolidated in one L2 vlan in order to connect to either of the ISR. this is what i guess. now does ether switch modules which comes integrated with ISRs can be made to behave like a normal 2950 switch?
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 23336572
1. Either way it is fine.

2. Correct.

3. L2 part is correct, but I don't know about the integrated stuff on ISR, never worked with an ISR.

Cheers,
Rajesh
0
 

Author Comment

by:nocss
ID: 23337873
Thanks Rajesh. i'll get back with some more queries tomorrow.hope yu wouldn.t mind.
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 23342399
It is a rule of EE that you can't overload the question, however if it is related to what you've asked then post back.

Cheers,
Rajesh
0
 

Author Comment

by:nocss
ID: 23351841
Sure Rajesh. last posting..

users will have their dg as the floating hsrp ip of that particular vlan. wish to know what should be the dg for the access switches.

i wish to have vlan1 as L3 vlan for acc swt as well as core swt for their identification/telnet purpose. any consideration in regards to hsrp for vlan1 in the core switches.
0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 500 total points
ID: 23352127
The active ip address of ASA would be used. When the active goes down, the secondary assumes the active ip. Hope that is clear.

Usually VLAN 1 is kept for management traffic only, it is deemed best.

Cheers,
Rajesh
0
 

Author Comment

by:nocss
ID: 23352196
Thanks Rajesh. will build the configuration.
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 23352518
You could assign the points by yourselves, don't you know how to do it?

Cheers,
Rajesh
0
 

Author Comment

by:nocss
ID: 23352927
NO
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 23353499
Ok, you should have the accept button on each answer and you can do it by selecting any of the answer. Also the help on this site would help you find it.

Cheers,
Rajesh
0
 

Author Closing Comment

by:nocss
ID: 31507874
satisfied with the answers provided. will help me building requisite configurations. THANKS..
0

Featured Post

Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Watchguard XTM 2 94
Cisco ASA 5506 - port forwarding not working 10 98
Cisco ASA 5505's for VPN study 15 60
TZ400 2 28
I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question