Solved

Juniper Core L3 switch with multiple VLAN's, gateway to ASA 5505

Posted on 2011-02-16
6
1,547 Views
Last Modified: 2012-05-11
I am having trouble getting a Juniper L3 EX2200 to pass  all traffic to a Cisco ASA 5505 that is my gateway. I have 5 VLAN's terminating on the Juniper switch, whcih has the default gateway of the ASA.

The ASA has routes to each VLAN IP pointing to the Junipers IP, which is currently member of VLAN 100 (example). I changed both the ASA port and the Juniper uplink port to Access only port, and still can not get through to the internet from other VLAN's, other than the VLAN 100.

Any thoughts?
0
Comment
Question by:munisee
  • 2
  • 2
  • 2
6 Comments
 
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 250 total points
ID: 34907071
Normally I would trunk the port on the juniper and create subinterfaces for each vlan on the ASA with an ip address in each vlan. I don't know if the 5505 is able to cope with that (depends on the limitations in the software).
0
 
LVL 18

Accepted Solution

by:
deimark earned 250 total points
ID: 34907260
As above, but also to add to this, if you can supply the routing table from the EX3200 and the interfaces configured ie does each vlan have its own l3-interface?

Cos if not, then you will need to trunk all the vlans to the ASA and let that do the routing (if it can have more than 1 vlan interface)
0
 

Author Comment

by:munisee
ID: 34910624
Ernie-- We actually want to have the Juniper switch do all the L3 routing. Not the 5505. If we used the 5505 we would cut speeds down to 100mbit. The Juniper is gig.

Deimark, Yeah, each VLAN does have it's own L3 interface, which is x.x.x.1, y.y.y.1, z.z.z.1, etc.  Like I had mentioned to Ernie the reason we didn't want to use the ASA for VLAN routing is that we would lose our Gig backbone switching capacity.

Anyway, I am going to split this with you guys as I found the issue myself. When the core switch was configured for a default GW, the subnet mask was 24 bits... not 0. So this was our issue!!! LOL.

Thanks for your responses!
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 

Author Closing Comment

by:munisee
ID: 34910629
Problem was resolved.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 34910853
Good to hear you resolved it!

Thx for your points :)
0
 
LVL 18

Expert Comment

by:deimark
ID: 34910954
As above, glad its now working  :)
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Suggested Solutions

It happens many times that access list (ACL) have to be applied to outgoing router interface in order to limit some traffic.This article is about how to test ACL from the router which is not very intuitive for everyone. Below scenario shows simple s…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now