Solved

ISP Migration w/Two Routers, Two ISPs, One Firewall...

Posted on 2009-07-13
2
484 Views
Last Modified: 2013-12-14
Okay I'll try to keep this as uncomplicated as possible but I've over thought this to the point where I'm just thinking of silly scenarios.

Current setup:
Two ISPs
Cisco 2691 Router (running BGP)
PIX 515e FW 6.3.3 (E0 = outside, E1 = inside, E2 = DMZ)
Full Class C of IP Addresses

We're dropping one provider & will be losing our block of IP addresses.  However, the new ISP is giving us a Full Class C.  The new ISP will serve as the primary & the other existing ISP will become our backup while running BGP.  They are giving us a new 2600 router (not sure exactly what model since they initially said 1841 & decided to go w/2600 series).

Okay so the primary concern is the DNS propagation.  Our ISP that we're dropping is giving us 30 days to get everything over to the new block of addresses, but I am trying to figure out how I can seamlessly transition to the new ISP since the PIX can is already set with the set of old IP addresses.  If I could enter in the new IP addresses in the NAT tables it wouldn't be a problem but we know that the 515e does not allow that.

The PIX outside interface is set to one of the public IP addresses that is in the block that we have to surrender.  I tried to set the new ISP address as a virtual interface & then plug in all the NAT but PIX said uh uh, no way.  I have around 200 NATs & another 200 or so Access Rules that I have to enter.

My last 'brilliant' idea was to configure the new router to connect to the old router.  Configure the old router to the IP address of the new router & basically have all the traffic from our new ISP pass through the old router until the DNS propagates & then enter in the new NATs & Access rules.  But that would still require plugging in all that info after the DNS propagates  & would also require changing the initial config of the new router to point to the firewall instead of the old router.  So, I'm fairly sure that idea is pretty horrible.

Ideas/Suggestions?  I'm feeling very scared & alone.....  okay just kidding, but it is annoying as you know what...
0
Comment
Question by:wfcraven12
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 19

Accepted Solution

by:
nodisco earned 500 total points
ID: 24844533
Hi

considering what you are planning, I think a properly planned hot cut is not going to leave you with much issues.  Trying to maintain a 'stateful' transition is not going to be 100% possible so i think its best to arrange it in such a way as to keep the impact and downtime to a minimum.  Having done several of these before - notepad is your best friend for this!

Ensure your new connection is up and routing correctly - test using a sample ip from your new class C and if possible, test from behind a nat device (another firewall or router)
Once you are happy with this new connection, create your changes list in notepad with all the relevant statements to amend the PIX config.
Remember to work in the correct order re making changes - re global statements, statics and xlates.
E.g.

no route outside 0.0.0.0 0.0.0.0 22.22.33.34
clear static
no global 10 (outside) interface
no ip address outside 22.22.33.33 255.255.255.224
ip address outside 44.44.55.55 255.255.255.0
global 10 (outside) interface
static (inside,outside) ..........
static (inside,outside) ..........
route outside 0.0.0.0 0.0.0.0 44.44.55.56
clear xlate

If you are using an outside switch , ensure you clear its arp cache and check the mac-address table so that the new ips point to the mac addresses of the PIX outside interface rather than the old ones.

Its a matter of planning it and having a testing template and a fallback.  Regardless of size, a properly planned changeover can be done in a few mins.  
0
 
LVL 8

Author Closing Comment

by:wfcraven12
ID: 31603006
Looks good to me.  I'm thinking this still may be a Friday 6pm cutover just to be on the safe side but you definitely helped me get my thoughts on this organized.  Thanks!
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Home internet speed 20 45
Netflix streaming problem 18 64
Cisco Switch VLAN voice and Data 2 42
Failover for DMVPN 3 30
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question