Solved

Understanding network configurations

Posted on 2010-09-16
13
777 Views
Last Modified: 2012-05-10
We have a network which has two MPLS connections that route from two ports on a Cisco ASA Firewall (default gateway) which sits just off the main network switch.

1)  MPLS 1 routes to our sister company (ERP related traffic only).
2)  MPLS 2 routes internal Internet traffic out via an ISP router.  Our ISP also provides an offsite firewall and domain hosting services.

The internal network IP range is as follows:

10.213.0.0/19 or 255.255.224.0 (10.213.0.1 – 10.213.31.254)      

(MPLS 2) The router network to the Internet is:

10.213.253.8/29 or 255.255.255.248 (10.213.253.9 – 10.213.253.14)

The ASA firewall has two IP address one internal and one external (10.213.10.1 and 10.213.253.9).
For various reasons I need to place a BLOXX device between the ASA firewall and the ISP router.  This device basically performs web monitoring and filtering for the internal network.  My question is how do I set this up?  The device will be configured in pass through mode and will be connected in line between the ASA firewall and the ISP router.  

From which IP range do I assign an IP address?  Will the default gateway for the device be the ISP router?  Do I assign internal DNS servers or DNS addresses of the ISP to the device?  
0
Comment
Question by:DHPBilcare
  • 7
  • 5
13 Comments
 
LVL 6

Expert Comment

by:kuoh
ID: 33697149
 I'm not familiar with BLOXX, but usually these types of filtering appliances are placed between the firewall and the internal network.  It is generally simpler to do it this way because you have full control of the internal network and any special routing needs.  You mentioned "various" reasons as the need to place it on the outside interface, can you perhaps elaborate on that?
0
 

Author Comment

by:DHPBilcare
ID: 33697328
It tends to slow down the ERP traffic to the sister company which is why the device is being moved outside the ASA firewall.  Our ISP also provide an external firewall which we pay for and they manage.  The ASA is new as is the ERP.  We simply want to move BLOXX to the outside of the ASA so that it filters the Internet traffic but not the internal ERP traffic.  In this sense the ISA is more of a router than firewall.

I simply need to understand which IP range to use.  At the moment BLOXX is inside the ASA on 10.213.0.1 address with the ASA as the default gateway.  When I move it outside the ASA does it go on the 10.213.253 range with the ISP as the gateway ?

Thanks for the comment.  
0
 
LVL 10

Expert Comment

by:ujitnos
ID: 33698789
When u move the BLOXX between the ASA and the  ISProuter, the IP that will be used to manage the BLOXX will be that of 10.213..253 range, as you will be placing the device between that network.
The IP that you give for this inline device is to manage it so the default gateway for the management ip of bloxx can point to ur ASA interface, 10.213.253.X.
0
 

Author Comment

by:DHPBilcare
ID: 33698894
Thanks or that.

The BLOXX device also asks for DNS server addresses?   Do I use the internal DNS servers that are inside the ASA?  Or point to the ISP?
0
 
LVL 10

Expert Comment

by:ujitnos
ID: 33699035
U can use internal or external..... but preferably use internal, as it may help resolve internal address if any.
0
 

Author Comment

by:DHPBilcare
ID: 33703298
I've set up the BLOXX device on a dual interface (pass through):

BLOXX Internal IP: 10.213.253.11
BLOXX External IP: 10.213.253.12
BLOXX Default Gateway: 10.213.253.9  (ASA Cisco outside firewall)

However internal clients timeout trying to access the Internet even though I can ping the Internet.  Should I change the default gateway on the BLOXX to the ISP router?  

BLOXX is not blocking anyhting.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 10

Accepted Solution

by:
ujitnos earned 500 total points
ID: 33703392
yes, if you have configured it in pass-through mode, the default gateway is your ISP router interfcae.
Is it transperant mode orexplicit mode?
0
 

Author Comment

by:DHPBilcare
ID: 33704386
BLOXX is set in transperant mode.

Just to confirm am I still ok to set the DNS addresses on BLOXX as my internal servers?
0
 
LVL 10

Expert Comment

by:ujitnos
ID: 33704421
Yes, its ok to set the DNS as your internal DNS server. If u have option to set secondary DNS server, set it as your ISP dns server.
0
 

Author Comment

by:DHPBilcare
ID: 33714658
I have set the default gateway to the ISP rotuer inteface but once BLOXX has booted I cannt access the Internet with IE timing out waiting for the web address to reply.  I can ping through successfully.
0
 

Author Comment

by:DHPBilcare
ID: 33727322
The end solution to enable the link to work was to static router on the BLOXX device device which points back to the netork insdide the firewall.  Thus:

Network: 10.213.0.0
0
 

Author Comment

by:DHPBilcare
ID: 33727341
As I was saying I set up a static route on BLOXX as follows that mapped back to the internal network:

Network: 10.213.0.0
Mask: 255.255.224.0
Gateway: 10.213.253.9

And all is working.
0
 
LVL 10

Expert Comment

by:ujitnos
ID: 33727537
Ok.. great.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now