Solved

Cisco ASA, HP Procurve 2910 VLANs

Posted on 2012-12-28
4
802 Views
Last Modified: 2012-12-31
I have a Cisco ASA 5510 as a firewall.  The main network switch is HP Procurve 2910.  I need to set up 4 Vlans.  Both the Cisco ASA and the Procurve 2910 have vlan/routing capabilities.  Which device is most appropriate setup the vlans on?  The attached image has a little more detail.
vlan-desc.JPG
0
Comment
Question by:jmichael18
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 17

Assisted Solution

by:jburgaard
jburgaard earned 167 total points
ID: 38728484
The Procurve 2910 is a L3-switch and capable of doing simple routing fast. The ASA as far as I remember only has 4 interfaces, but has more advanced rule-set.
So my 2 cent: Make the vlans and the vlan-routing on 2910 and the inside/outside/dmz routing on the ASA.
0
 
LVL 20

Assisted Solution

by:rauenpc
rauenpc earned 167 total points
ID: 38728508
I agree with jburgaard, but would add in that the guest vlan should go to the Asa for layer 3 routing/firewall. All other vlans should use the 2910 for routing.
0
 
LVL 37

Accepted Solution

by:
ArneLovius earned 166 total points
ID: 38729211
I would agree with rauenpc, use the L3 switch as the defult gateway for all internal networks, and DMZ or Guest networks should terminate on the ASA

The 5510 has 4 ports, if you have the sec-plus licence, ports 0 and 1 are gigabit, ports 2 and 3 are 10/100

As some QoS rules can only be applied to a physical interface, this might affect how you terminate the connections to the ASA.
0
 

Author Closing Comment

by:jmichael18
ID: 38732657
Thanks for the valuable input!
0

Featured Post

MS Dynamics Made Instantly Simpler

Make Your Microsoft Dynamics Investment Count  & Drastically Decrease Training Time by Providing Intuitive Step-By-Step WalkThru Tutorials.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question