Solved

Cisco ASA 5505 Vlan config to Proxy Server

Posted on 2010-11-09
8
1,257 Views
Last Modified: 2012-05-10
Hello Everyone,

I'm confused on a cisco asa 5505 router setup I'm working.  Not sure at this point if the problem is my router or my proxy server.

I have configured the cisco router for Vlan1 and Vlan2 traffic going out eth0 (default route).  The eth0 interface connects to the "inside" interface of the proxy server.  Proxy then prompts for authentication and sends the outgoing packet to the "outside" interface that faces the Internet.

My problem is when I connect multiple devices on either vlan1 or vlan2 my proxy server only see's the connections as a single connection.  The proxy server shows the MAC of the cisco's eth0 interface from the Cisco router.

I'm new with Vlan's.  Does the traffic going out eth0 on the cisco box all get tagged with the MAC of the eth0 interface?  Is there a way to configure my router to display the MAC of the requesting device?  Otherwise I don't see how the proxy server can determine how many devices are requesting Internet access.

I attached my network map in PDF.

I appreciate your input and hope to understand this very soon.

Thank you,
Tim.
AlaskaGeeks-NETWORK-DIAGRAM.pdf
0
Comment
Question by:AlaskanGeeks
  • 4
  • 3
8 Comments
 
LVL 9

Expert Comment

by:avilov
ID: 34099094
Sounds like you route on that cisco. If you want your proxy to see MACs you need to switch. Trunking that eth0 may help
0
 
LVL 9

Expert Comment

by:gavving
ID: 34107230
The way you describe it is the correct way for it to work.  VLAN1 is the inside network and traffic routed from it to the Outside VLAN2 is going all show as coming from the Cisco eth0 MAC address like your seeing.   To have your proxy server see the inside users directly you'd have to have the traffic go through it first before it gets to the ASA.  

I'm guessing that you wanted to use the proxy server for the "public wifi" as well as the internal users.  
You could configure users to connect to the IP of the proxy server and have the Proxy server inside the network on VLAN1.  But then VLAN2 users on the public wifi would still show originating from the MAC address of the ASA.

0
 

Author Comment

by:AlaskanGeeks
ID: 34108355
Thank you for posting!   My goal here is to seperate the public from the private traffic then have the proxy server filter devices requesting Internet access.  

I thought maybe there is a router configuration that would enable us to VLAN the traffice first and then proxy it.  

I'm thinking that maybe I need to subnet the two networks, run them all through and unmanged switch, and then proxy, and finally route.  

If this is not possible is there another solution?

I'm working with:

Cisco ASA 5505 router
Dell PowerConnect 2816 16 Port Switch

Tim
0
 
LVL 9

Expert Comment

by:gavving
ID: 34141572
Sorry I've not responded.  Adding a proxy server to the ASA configuration complicates things.  
Can you add more NIC's to the proxy server and thus have it sitting on the "inside" of both VLANs before the traffic gets to the ASA?
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 

Author Comment

by:AlaskanGeeks
ID: 34147406
I don't see a way to add a second nic to the proxy.  I'm really feeling stuck here as I need to revisit basic networking.

I was thinking I could subnet the two networks into /16 and /24 subnet masks.  Then assigning all clients with a /24 default gateway which would be proxy server's incoming nic.  Then send it out the proxy and through the ASA box.

We did a mock up with packet tracer and can not ping between the two subnets.  We can ping the gateway from both subnets.

Please tell me if my theory is flawed.  My goal again is to keep the private netwrok in accessible to the public network.

Thank you for your consideration,
Tim
0
 
LVL 9

Expert Comment

by:gavving
ID: 34148172
Does this proxy server have to be configured 'in-line', or can it be configured as a single-homed device?   Can you configure multiple IPs on the Proxy's inside facing interface?  Maybe you can configure the Proxy to have it's inside interface physically plugged into both VLANs but accessible on different IP ranges?  

Getting one proxy server to work with both VLANs in the manner in which you want is not going to be easy to do, and maintain security.  
0
 

Accepted Solution

by:
AlaskanGeeks earned 0 total points
ID: 34297675
I had to rework the network topology.  I could not NAT any packets until after they passed through the proxy server.  Therefore we separated the network traffic by sub-netting.  Then passed both sub-nets through the proxy allowing the server to apply filtering.  Finally out the ASA box.
0
 

Author Closing Comment

by:AlaskanGeeks
ID: 34328713
I don't think points are necessary as there is no clear solution.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to setup PLEX PLUS on 2 computers 2 43
Fortigate 100D NTP Issue 4 50
Cisco 2911/Etherswitch: Bringing up SVI and not seeing vlan on one side of trunk 7 34
DHCP Server 14 62
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now