Solved

Help configuring a Cisco RV082 Dual WAN VPN router/gateway with a Cisco ASA-5510.

Posted on 2011-03-19
4
1,731 Views
Last Modified: 2012-05-11
Thanks in advance for your help!

I have a problem and Cisco can't seem to help me figure it out....
What I am trying to do:

1.  Using two external T1 internet connections that come from two entirely different service providers.
2.  Bind those T1’s together using the load balancing functionality of a Cisco RV082 dual WAN VPN router/gateway.
3.  Place the RV082 in front of a Cisco ASA-5510 that is currently in place and managing DHCP, Firewall security, NAT configurations and PAT into a LAN of roughly 50 end users.

::this might help:: or it might just confuse…


--WAN-1 = 216.205.209.138 / 255.255.255.248
              +
--WAN-2 = 69.95.127.130 / 255.255.255.240
-(Auto Load Balancing)          
-------RV082-------
            *
              *
            *
            *
|——ASA-5510——|
- Outside Interface === (currently bound to WAN-1 @ 216.205.208.138-)
-(NAT and PAT rules for various servers and services outside/in & inside/out are set and working between WAN1 -and the internal LAN)
- Inside Interface   === (LAN -192.168.1.1-)
             *
           *
             *
           *
- Internal Network Servers and End User Workstations - 192.168.1.2 - 192.168.1.254
- I have a wide span of external IP addresses that NAT or PAT through the ASA-5510 to private IP's of different web servers and FTP servers.
-----------------------------------

more info:
In 7 months the contract for the WAN-1 service provider is ending.  We brought the connection for WAN-2 in to prep for that contract end date and to take advantage of a really good price.

I really want to increase our speed around here. Offloading some traffic heavy services like FTP to a different WAN away from but still internally accessible to my end users. I thought this was an easy solution and a fun project.  Instead it's turned into a mess!
If the above is just some crazy dream of mine that only makes sense to me please let me know.
I am open to any suggestions, besides giving up. ;)



0
Comment
Question by:ReproGraphix
4 Comments
 
LVL 26

Assisted Solution

by:akahan
akahan earned 250 total points
ID: 35173630
You haven't said what the problem is.   Which part of this isn't working?

You would want to set the outside interface of the ASA5510 to a LAN address on the RV082's LAN side (after changing the RV082's default LAN address to something other than 192.168.1.1, e.g., 192.168.0.1, so it doesn't conflict with your existing LAN on the LAN side of the ASA.)

By the way, you mention that "Outside Interface === (currently bound to WAN-1 @ 216.205.208.138-)," but it should be bound to 216.205.209.138 (see the typo?)  If that's accurate, no wonder nothing's working!

0
 
LVL 79

Accepted Solution

by:
lrmoore earned 250 total points
ID: 35175600
>I have a wide span of external IP addresses that NAT or PAT through the ASA-5510 to private IP's of different web servers and FTP servers
This is going to be the biggest challenge for you. As akahan alludes to above, you need a transit network between the LAN on the RV082 and the WAN port of the ASA. This will probably have to be a private network.
You will have to let the RV082 do the natting from public to private. You can create multiple 1-1 static nat's on the RV082 that correspond to static NAT's on the ASA. For example:

RV082 WAN1 - 216.205.209.138
RV082 WAN2 - 69.95.127.130
RV082 LAN - 192.168.255.1 /24
Static NAT
  216.205.209.139 - 192.168.255.139
  216.205.209.140 - 192.168.255.140
  216.205.209.141 - 192.168.255.141

ASA WAN - 192.168.255.2
ASA Default gateway 192.168.255.1
ASA Static NAT
  192.168.255.139 - 192.168.1.xx
  192.168.255.140 - 192.168.1.xy
  192.168.255.141 - 192.168.1.yy

<etc>
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 35496527
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Hello to you all, I hear of many people congratulate AWS (Amazon Web Services) on how easy it is to spin up and create new EC2 (Elastic Compute Cloud) instances, but then fail and struggle to connect to them using simple tools such as SSH (Secure…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now