Parallel run two firewall
Posted on 2011-05-04
In order to deploy a new firewall for test, I have the following setup but somehow I found some problem. Before deploy the new firewall for production, the old firewall still up and running for daily operations.
Port 1 -> int1 interface on new firewall
Port 2 -> int2 interface on new firewall
Port 3 -> Cable modem for cable connection (Secondary ISP)
Port 4 -> ADSL modem for internet connection (Primary ISP)
Port 5 -> Old firewall 1st WAN port
Port 6 -> Old firewall 2nd WAN port
Port 8 -> Uplink to LAN Switch port 16 (Using X-over cable)
Port 1 -> LAN interface on new firewall (ip 192.168.0.254)
Port 2 -> LAN interface on old firewall (ip 192.168.0.1)
Port 16 -> Uplink to WAN Switch port 8
The ADSL has two sets of public ip address assigned, one set for old firewall and one set for new firewall. Same as cable modem, therefore I have separate public ip address in my test.
ip 192.168.0.1 is the gateway ip for all production computer
ip 192.168.0.254 is the proposed new gateway ip, will be assigned to all computer once the test is perfect.
Here is my problem, I found that if I connect like this, I am not able to ping 192.168.0.1 from the production computer until I disconnect cable from Port 4 on WAN switch and connect the ADSL Ethernet port and the old firewall WAN port directly.
What is the problem here? If I am not able to access to 192.168.0.1 gateway, the production computer cannot access site to site vpn back to HQ.