Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Cisco ASA, HP Procurve 2910 VLANs

Posted on 2012-12-28
4
Medium Priority
?
803 Views
Last Modified: 2012-12-31
I have a Cisco ASA 5510 as a firewall.  The main network switch is HP Procurve 2910.  I need to set up 4 Vlans.  Both the Cisco ASA and the Procurve 2910 have vlan/routing capabilities.  Which device is most appropriate setup the vlans on?  The attached image has a little more detail.
vlan-desc.JPG
0
Comment
Question by:jmichael18
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 17

Assisted Solution

by:jburgaard
jburgaard earned 668 total points
ID: 38728484
The Procurve 2910 is a L3-switch and capable of doing simple routing fast. The ASA as far as I remember only has 4 interfaces, but has more advanced rule-set.
So my 2 cent: Make the vlans and the vlan-routing on 2910 and the inside/outside/dmz routing on the ASA.
0
 
LVL 20

Assisted Solution

by:rauenpc
rauenpc earned 668 total points
ID: 38728508
I agree with jburgaard, but would add in that the guest vlan should go to the Asa for layer 3 routing/firewall. All other vlans should use the 2910 for routing.
0
 
LVL 37

Accepted Solution

by:
ArneLovius earned 664 total points
ID: 38729211
I would agree with rauenpc, use the L3 switch as the defult gateway for all internal networks, and DMZ or Guest networks should terminate on the ASA

The 5510 has 4 ports, if you have the sec-plus licence, ports 0 and 1 are gigabit, ports 2 and 3 are 10/100

As some QoS rules can only be applied to a physical interface, this might affect how you terminate the connections to the ASA.
0
 

Author Closing Comment

by:jmichael18
ID: 38732657
Thanks for the valuable input!
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question