Solved

Help me understand this network configuration.

Posted on 2012-03-20
15
518 Views
Last Modified: 2012-03-21
While I have knowledge and experience, I'm no networking expert. I'm having trouble wrapping my head around this configuration, as it seems to be looping.

Two pieces of hardware, a Cisco 3750, and an ASA5520. I'd rather not post the full configs. The 3750 is handling all of the internal VLAN routing. Here are what I believe to be the relevant commands:

3750:
interface GigabitEthernet1/0/12
  no switchport
  ip address 10.1.101.2 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 10.1.101.1
====================
ASA:
interface GigabitEthernet0/0
  nameif outside
  ip address 72.x.x.x 255.255.255.224
!
interface GigabitEthernet0/1
  nameif inside
  ip address 10.1.101.1 255.255.255.0
!
global (outside) 72.x.x.x netmask 0.0.0.0
nat (inside) 101 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 72.x.x.x 1
route inside 10.1.1.0 255.255.255.0 10.1.101.2 1
route inside 10.1.20.0 255.255.255.0 10.1.101.2 1
route inside 10.1.21.0 255.255.255.0 10.1.101.2 1
etc.
=====================

There is a cable connecting Gi0/1/12 to Gi0/1, passing through a passive web filter. It seems like the 3750 is sending everything to the ASA, which is sending everything back to port 12 on the 3750?

No, no, I'm wrong. I thought the 3750 was doing the routing, but really it's the ASA. Right? Either way, this seems very inefficient. If that's the case, it seems like all our internal traffic is passing through the web filter twice! Surely that's exponentially increasing the load on the filter!

Anyhow, any insight anyone can offer is appreciated. If I need to provide further info, just let me know.

Thanks.
0
Comment
Question by:LSDIT
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
  • 4
  • +2
15 Comments
 
LVL 6

Expert Comment

by:vmagan
ID: 37744591
what are you asking here?
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37744600
I'm not sure what you mean by the webfilter. To me it looks like the ASA is the default gateway for the 3750.
So what exactly do you mean when saying  it seems like all our internal traffic is passing through the web filter twice ?
0
 
LVL 10

Expert Comment

by:pclinuxguru
ID: 37744605
what it say in your 3750 config for gi0/12 which is what I am assuming your speaking of when you say it is sending it back.

my other question would be...
1) can you ping  10.1.101.2 from your different networks.
2) Can you ping 10.1.101.1 from the various networks as well as from the 3750
3) Can you ping from your asa to various addresses in your network?
0
Creating Instructional Tutorials  

For Any Use & On Any Platform

Contextual Guidance at the moment of need helps your employees/users adopt software o& achieve even the most complex tasks instantly. Boost knowledge retention, software adoption & employee engagement with easy solution.

 

Author Comment

by:LSDIT
ID: 37744608
There's a passive web filter inline between the devices. The IP is actually 10.1.101.3. The cable goes from Gi0/1/12 on the 3750 to the LAN port on the filter, and from the WAN port on the filter to Gi0/1 on the ASA. I'm calling it a passive filter because it's not specifically addressed in the routing, it works by being plugged inline.

As for what I'm asking, I suppose whether the config makes sense and if it's as inefficient as it seems to me.
0
 

Author Comment

by:LSDIT
ID: 37744614
I'm sorry.

I should have been clear from the start that EVERYTHING WORKS FINE. There are no problems, I was just looking into replacing the web filter, so I was looking through the configs to see what would be involved.
0
 
LVL 6

Accepted Solution

by:
vmagan earned 500 total points
ID: 37744633
The 3750 switch is sending traffic to the ASA which is your DEFAULT GATEWAY.


3750:
interface GigabitEthernet1/0/12
  no switchport
  ip address 10.1.101.2 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 10.1.101.1  (this line indicates that the switch sends everything to the ASA which is 10.1.101.2)

everything looks fine here and nothing is being duplicated or being routed twice.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37744634
Well I don't see anything inefficient (yet ;).
The ASA is the default gateway for the 3750. There is a (seemingly transparent) web filter in between. All traffic that is not destined for your network goes out the default gateway (ASA) on to the internet and gets back through the ASA (and the webfilter) to your network: the 3750.
Makes perfect sense to me. But of course that could be because I (we) have limited information.
0
 
LVL 6

Expert Comment

by:vmagan
ID: 37744644
lol, yes we do Erniebeek. very limited info.

But if you want to add a webfilter nothing here would be replaced. You would just add this web filter as a proxy server depending on what you get. The toplogy that you have now will not change except for the addition of adding the web filter.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37744679
@vmagan: can't be too carefull :)

But seriously. As I understand, LSDIT wants to replace the webfilter. As it is transparent (or as far as we can see it is), there would be no impact on the configs of the switch or the ASA as long as it is replaced with another transparent webfilter.
0
 
LVL 6

Expert Comment

by:vmagan
ID: 37744688
yup, everything should remain the same.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37744744
Glad we agree ;)
0
 

Author Comment

by:LSDIT
ID: 37744999
Ok, when I started the question, it seemed like traffic was looping. Then I realized that only traffic bound for another internal ip would be routed to 10.1.101.2. But I figured I'd still ask, since it still seems like having all our internal inter-vlan traffic pass through the web filter, to the firewall, back through the filter, back to the 3750 just seems very inefficient.

Also, the filter I want to move to is already in place in another network, and I will have to route the traffic over to it, and configure it to route the traffic back. But that's a whole different issue that I'm not looking for help with (yet).
0
 
LVL 6

Expert Comment

by:vmagan
ID: 37745688
We can get started with the new question whenever you're ready. Is this question completed?
0
 
LVL 8

Expert Comment

by:gsmartin
ID: 37747469
FYI...  The Cisco 3750 is still doing your VLAN routing.  The route on the 3750 is your gateway of last resort for all Internet bound traffic.  The internal routes on your ASA tells the firewall where to where to go for different subnets/VLANs to your internal network.
0
 

Author Comment

by:LSDIT
ID: 37747920
THANK YOU. Exactly the clarification I was looking for.
0

Featured Post

Are You Ransomware's Next Victim?

Worried about ransomware attacks hitting your organization?  The good news is that these attacks are predicable and therefore preventable. Learn more about how you can  stop a ransomware attacks before encryption takes place with WatchGuard Total Security!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question