Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Help with routing between networks

Posted on 2013-01-11
Medium Priority
Last Modified: 2013-01-13
In my foray into the Cisco realm, I recently configured an ASA with access to the internet via static public IP (see blue shaded area of attached topology).  The green shaded area of the topology represents a different subnet connected to the ASA.  I configured the ASA to perform NAT for both of the following networks:
I verified that both of the above could reach the internet.

What I am having difficulty with is configuring both the router and the ASA to allow communication with each other from the network to the network.  I've been reading through CCNA materials and have tried to follow lab examples, but can't seem to get it working.  I enabled EIGRP on both and verified that routes are being advertised.  I know I missing something.  

My goal is understand the commands required under the different platforms (ASA 9.0 and IOS 15) and learn the most efficient way of establishing communication between the two subnets.  Also, I need to fill my knowledge gaps.  

Please see the attached topology, ASA configuration, and router configuration.  Thank you all in advance for taking a look!
Question by:J3ckyl
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 20

Expert Comment

ID: 38770016
Same-security-traffic permit intra-interface

By default an Asa will not allow hairpin routing so you'll need to enable it.

Author Comment

ID: 38770680
Thanks rauenpc.  I entered that command into the ASA cli, but nothing changed.  From hosts on the network, I can ping the interface, but not hosts on the network. I still cannot ping hosts on the network from the network.  I appreciate the input. Any other areas I should look at?  I am completely new to ASA and I wondering if I have to configure ACL's to specifically allow the two networks to communicate.
LVL 20

Accepted Solution

rauenpc earned 1500 total points
ID: 38771058
It would appear that you have split routing. If the devices on the 10 network have the Asa set as a default gateway, that means that traffic uses the Asa one direction for routing, but the opposite direction the Asa is only used for switching based on your diagram. The Asa would, by default, classify all the traffic as half open and drop packets.
Personally, I would layout the network Internet -- Asa -- router -- switch. The switch can have two vlans, the router can do routing, and the Asa does the firewalling. This way the Asa doesn't need to worry about routing beyond inside/outside.

Author Comment

ID: 38771402
Thanks, I'll mark that as a solution.  While that definitely is a solid solution and makes for a cleaner network, for the sake of learning, what would I need to correct the current situation?
LVL 20

Expert Comment

ID: 38772818
You would need to either
set all the 10.x devices to use the router as a default gateway
add static routes on all devices in the 10.x network to use the router when going to the 172.x network
configure state bypass on the asa for that particular traffic. State bypass essentially ignores the state of traffic and just lets it route with no care as to half open connections, or any other possible attack.

A neat thing that you can do if you're using a windows DHCP server, is set option 249. Option 249 is the Classless IP static route option, and it pushes down a set of static routes to any machine that requests it. Windows machines do request that option by default. The option allows you to specify a subnet and a gateway to use for this. In your case, you would only need this in the 10.x subnet. Although this works, I wouldn't really suggest this in a production network except as a bandaid while working through a better solution such as redesigning the layout to mitigate the need for such static routes. I don't know if any non-windows devices accept option 249, so any linux/unix machines or printers would still have an issue.

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question