wspjones99
asked on
ASA 5505 config with multiple WAN IPs
Hi,
I would like to replace our watchguard filewalls with Cisco ASAs. What is the capability of multiple public IP addresses? I have a block of 6 that I have setup on the WatchGuard box, and they are all bound to the external NIC and are configured to route to different internal servers/services. I did try to configure an ASA 5510 at another site in a similar manor. I had port 0 ast the main wan connection, then I tried to configure port 1 with the next public IP in our range, and it told me I could not have the 2nd IP, the subnet range overlapped. So, is there an easy way to assign more then one public IP to the ports on the ASA like the WatchGuard?
Thanks - Wayne
I would like to replace our watchguard filewalls with Cisco ASAs. What is the capability of multiple public IP addresses? I have a block of 6 that I have setup on the WatchGuard box, and they are all bound to the external NIC and are configured to route to different internal servers/services. I did try to configure an ASA 5510 at another site in a similar manor. I had port 0 ast the main wan connection, then I tried to configure port 1 with the next public IP in our range, and it told me I could not have the 2nd IP, the subnet range overlapped. So, is there an easy way to assign more then one public IP to the ports on the ASA like the WatchGuard?
Thanks - Wayne
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Hi ffleisma,
We are trying to the ASA for the following:
1. SSL and outlook over the internet going to mail.domain.local
2. Cisco SSL vpn client
3. Sharepoint to sharepoint.domain.local
I am not sure if the exchange box and the sharepoint box need separate wan IP addresses due to port 80.
I got around the OWA/ smart phone SSL issue by assigning port 444 for the SSL vpn client, using the same public IP for both. But what I would like to do is use three of the public ip addresses, one for exchange, one for sharepoint, and one for the cisco SSL vpn. In the watchGuard box it is fairly simple to add a second, third, etc.. public IP to the wan NIC and then setup the port mappings to the separate lan IPs. I am proposing to replace the WatchGuard box with a cisco ASA, and want to be sure we can support what is already setup.
Clear as mud huh?
Thanks - Wayne
Thanks - Wayne
We are trying to the ASA for the following:
1. SSL and outlook over the internet going to mail.domain.local
2. Cisco SSL vpn client
3. Sharepoint to sharepoint.domain.local
I am not sure if the exchange box and the sharepoint box need separate wan IP addresses due to port 80.
I got around the OWA/ smart phone SSL issue by assigning port 444 for the SSL vpn client, using the same public IP for both. But what I would like to do is use three of the public ip addresses, one for exchange, one for sharepoint, and one for the cisco SSL vpn. In the watchGuard box it is fairly simple to add a second, third, etc.. public IP to the wan NIC and then setup the port mappings to the separate lan IPs. I am proposing to replace the WatchGuard box with a cisco ASA, and want to be sure we can support what is already setup.
Clear as mud huh?
Thanks - Wayne
Thanks - Wayne
It is totally clear. Just do what I wrote above and you will be home free!
/Kvistofta
/Kvistofta
ASKER
That was what I was looking for!
But this is only for outbound traffic, since you cannot "move" your public ip:s from one ISP-connection to another without the use of BGP which the ASA doesnt support.
More info:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml
/Kvistofta