Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Cisco ASA, HP Procurve 2910 VLANs

Posted on 2012-12-28
4
Medium Priority
?
804 Views
Last Modified: 2012-12-31
I have a Cisco ASA 5510 as a firewall.  The main network switch is HP Procurve 2910.  I need to set up 4 Vlans.  Both the Cisco ASA and the Procurve 2910 have vlan/routing capabilities.  Which device is most appropriate setup the vlans on?  The attached image has a little more detail.
vlan-desc.JPG
0
Comment
Question by:jmichael18
4 Comments
 
LVL 17

Assisted Solution

by:jburgaard
jburgaard earned 668 total points
ID: 38728484
The Procurve 2910 is a L3-switch and capable of doing simple routing fast. The ASA as far as I remember only has 4 interfaces, but has more advanced rule-set.
So my 2 cent: Make the vlans and the vlan-routing on 2910 and the inside/outside/dmz routing on the ASA.
0
 
LVL 20

Assisted Solution

by:rauenpc
rauenpc earned 668 total points
ID: 38728508
I agree with jburgaard, but would add in that the guest vlan should go to the Asa for layer 3 routing/firewall. All other vlans should use the 2910 for routing.
0
 
LVL 37

Accepted Solution

by:
ArneLovius earned 664 total points
ID: 38729211
I would agree with rauenpc, use the L3 switch as the defult gateway for all internal networks, and DMZ or Guest networks should terminate on the ASA

The 5510 has 4 ports, if you have the sec-plus licence, ports 0 and 1 are gigabit, ports 2 and 3 are 10/100

As some QoS rules can only be applied to a physical interface, this might affect how you terminate the connections to the ASA.
0
 

Author Closing Comment

by:jmichael18
ID: 38732657
Thanks for the valuable input!
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question