Solved

ASA 5505 config with multiple WAN IPs

Posted on 2010-08-30
7
4,683 Views
Last Modified: 2012-08-05
Hi,
I would like to replace our watchguard filewalls with Cisco ASAs.  What is the capability of multiple public IP addresses?  I have a block of 6 that I have setup on the WatchGuard box, and they are all bound to the external NIC and are configured to route to different internal servers/services.  I did try to configure an ASA 5510 at another site in a similar manor.  I had port 0 ast the main wan connection, then I tried to configure port 1 with the next public IP in our range, and it told me I could not have the 2nd IP, the subnet range overlapped.  So, is there an easy way to assign more then one public IP to the ports on the ASA like the WatchGuard?
Thanks - Wayne
0
Comment
Question by:wspjones99
7 Comments
 
LVL 9

Assisted Solution

by:ffleisma
ffleisma earned 150 total points
ID: 33560747
its not a problem with assigning two or more public IP for the ASA, it can handle having multiple public IP address. The problem you encountered is having two interfaces on the same subnet, hence the ASA didn't allow it.

having 1 ISP, though you have 6 public ip addresses, all of those are within the same subnet. Just considered it like configuring a router, you can't place two interfaces on the same subnet.

now, considering your requirement, can you further explain why you need to map you 6 public ip address on the ASA? can you explain the setup you wish to accomplish? be glad to help you out

hope this helps :-)
0
 
LVL 17

Expert Comment

by:Kvistofta
ID: 33560900
The ASA supports "dual isp" with SLA route tracking. That means that you get a redundant outbound internet-connection since the ASA tracks the primary ISP. If it fails the default route will be removed and the "secondary" default route pointing to the secondary ISP will become active.

But this is only for outbound traffic, since you cannot "move" your public ip:s from one ISP-connection to another without the use of BGP which the ASA doesnt support.

More info:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

/Kvistofta
0
 
LVL 4

Assisted Solution

by:Zupreme
Zupreme earned 150 total points
ID: 33561061
This is very easy to do with a Cisco ASA.

Just configure one interface IP and configure the other IP addresses as static entries.

You can read more about configuring static entries on an ASA here: http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008046f31a.shtml
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 
LVL 17

Accepted Solution

by:
Kvistofta earned 200 total points
ID: 33561154
Just to clearify Zupremes comment:

You only put one ip-address of the public range onto the outside interface. Lets say that you have 123.123.123.0/28 which gives you ip .1 to .14 to use and the ISP uses .15:

interface e0/0
 nameif outside
 security-level 0
 ip address 123.123.123.1 255.255.255.240

If you wanna allow inbound www-traffic to internal hosts 10.0.0.2 and 10.0.0.3 behind 123.123.123.2 and 123.213.123.3 respective you do like this:

static (inside,outside) 123.123.123.2 10.0.0.2

static (inside,outside) 123.123.123.3 10.0.0.3

access-list acl_outside ext permit tcp any host 123.123.123.2 eq www
access-list acl_outside ext permit tcp any host 123.123.123.3 eq www
access-group acl_outside in interface outside

For each public IP you want to translate inbound you just add a static and allow the traffic in the outside acl. In Cisco-world you dont assign those extra addresses to the outside interface like you do with some other vendors.

/Kvistofta

0
 

Author Comment

by:wspjones99
ID: 33561570
Hi ffleisma,
We are trying to the ASA for the following:
1. SSL and outlook over the internet going to mail.domain.local
2. Cisco SSL vpn client
3. Sharepoint to sharepoint.domain.local
I am not sure if the exchange box and the sharepoint box need separate wan IP addresses due to port 80.
I got around the OWA/ smart phone SSL issue by assigning port 444 for the SSL vpn client, using the same public IP for both.  But what I would like to do is use three of the public ip addresses, one for exchange, one for sharepoint, and one for the cisco SSL vpn.  In the watchGuard box it is fairly simple to add a second, third, etc.. public IP to the wan NIC and then setup the port mappings to the separate lan IPs.  I am proposing to replace the WatchGuard box with a cisco ASA, and want to be sure we can support what is already setup.
Clear as mud huh?
Thanks - Wayne
Thanks - Wayne
0
 
LVL 17

Expert Comment

by:Kvistofta
ID: 33561598
It is totally clear. Just do what I wrote above and you will be home free!

/Kvistofta
0
 

Author Comment

by:wspjones99
ID: 33561860
That was what I was looking for!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are many useful and sometimes not well documented or forgotten IOS or ASA/PIX commands. See IPE article here , there was also one on PacketU and on Cisco Tips & Tricks. Below are my favorites. I give also a few most often used for Cisco IPS an…
This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question