Solved

Can the ASA redirect traffic to another device on same LAN?

Posted on 2008-11-01
3
1,604 Views
Last Modified: 2012-05-05
Imagine three devices on the inside LAN of a Cisco ASA.  And there is a remote WAN site 10.1.2.0/24.  

A  10.1.1.1 is the ASA and is the gateway to the Internet.
B   10.1.1.5 is a Cisco 2811 router with a WAN connection to another site.
C   10.1.1.100 is a workstation - say a Windows PC.

Station C has a default gateway of 10.1.1.1 and pings 10.1.2.200.  Will the ASA station A direct the packet to the 2811 station B for delivery to the remote WAN site?  Or is it the case that a packet that enters
and interface on an ASA can not come back out to another device on the LAN?  Any reference would be appreciated.  Thank-you.
0
Comment
Question by:amigan_99
  • 2
3 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 250 total points
ID: 22858753
>>Station C has a default gateway of 10.1.1.1 and pings 10.1.2.200.  Will the ASA station A direct the packet to the 2811 station B for delivery to the remote WAN site?  Or is it the case that a packet that enters and interface on an ASA can not come back out to another device on the LAN?

It is the latter case.  The packet will not come back out the same interface that it entered.  There is an exception to this rule, but it is for VPN traffic only, not for the type of traffic that you are talking about.  You need a true router to perform this type of routing.  You can always set the 2811 router as your default gateway for all of the 10.1.1.x hosts, but you may not want to do this in your scenario.
0
 
LVL 1

Author Comment

by:amigan_99
ID: 22858832
Thanks batry - I seemed to recall that was the case - as you describe.  The other option I have in this case is to make the 3750 switches route in addition to switching.  I purchased enhanced image so that's likely what I will do when it's time to implement.
0
 
LVL 1

Author Closing Comment

by:amigan_99
ID: 31512367
Thank-you.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now