troubleshooting Question

Cisco 2801 Router as a Default Gateway for ISP

Avatar of JustinBMak
JustinBMak asked on
BroadbandNetworking Hardware-OtherNetwork Security
5 Comments1 Solution1002 ViewsLast Modified:
EE Folks:

I have a fiber internet connection that goes to a Cisco ME3400 (Fiber to Copper Converter) and then my new ASA5510 (directly - asa5510 is set up in routed mode). My ASA5510 keeps getting knocked offline due to the enormous amount of TCP packets out of sync I am receiving from my ISP. I called the ISP and they said my line is basically a Layer 2 link and that there is no routing. Cisco Engineer states I need to put a router between the ASA and my first hop (the Cisco ME3400).

So I am trying to work on this, I have it configured as I was going to put the Cisco ASA in transparent mode however an engineer at Cisco has informed me that it is not recommended due to the fact I use NATing for multiple things include my web server and for my consultants remote access.

So with that being said, I need to see what the best possible solution is. I would assume as the one Cisco Eng. stated is to put up a router but I wouldn't think you would want two routers on the same network - right? It's not best practice and a section of the CCIE Security KB is that you want a router in between your ASA and your ISP. So if this is all true, how would I set up the Router to be basically a gateway like how the folks at AT&T do when you get a bonded T1 circuit?

I "think" basically I would want the Cisco Router to be a gateway router to where the ASA can have one of my 16 IPs and set the ASA's default gateway as the Cisco 2801 but not sure how that would pass over to the Cisco ME3400 because obviously I need it!

Plus I am in the process of purchasing a Cisco 2Port Fast Ethernet WIC Card because I have two ISP and I am going to set up fail over on

I'm sure there will be tons of questions so please ask away! I am eager to set this up or return the ASA and go back to Sonicwall.
ASKER CERTIFIED SOLUTION
ArneLovius

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 5 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 5 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros