Solved

ASA at the PUBLIC/PRIVATE edge. /29 subnet - need to use one of 6 public IP's for dual edge firewall

Posted on 2013-02-02
3
545 Views
Last Modified: 2013-02-02
Hi,

Ill Try and explain :)

Our ISP routes to our /29 subnet. - I imagine to do so they route to our outside interface of our ASA. We have no router attached to the outside interface of our ASA. The outside interface of ASA is attached to a L2 Cisco switch - and then cabled out to net. - I'm presuming then that our ISP's gateway to our subnet is the public IP of the outside interface of our ASA

Ok - with a /29 subnet I have further public IP's to use. - I want to buy a co-edged Polycom firewall for vid-conference. I want to plug the outside interface of this polycom firewall into the external Cisco switch and give it one of our 6 public Ip's. (it will therefore be separate from the ASA. The polycoms firewalls internal interface will then plug into our internal LAN. The vid-conference internally will be on separate vlan to data (internal core switches)

The question I have is will this work? The traffic destined for the polycom outside interface will hit the outside interface of the ASA.(as a route back to the /29 subnet) But then what - Is it so that an ASA wont send traffic out the interface it received on.? to reach the polycom- Or will ARP somehow take care of it ? - discovering the outside interface IP of the polycom?

Sorry this might be simple answer - but I'm unsure if this will work. Thanks - If not what do I need to do. We have 6 public IP's - Do I need an external router outside of ASA - or is there another way? - thanks
0
Comment
Question by:philb19
  • 2
3 Comments
 
LVL 27

Accepted Solution

by:
davorin earned 500 total points
Comment Utility
I'm not sure that I understand your question completely, but I will try to answer you.
Your ISP has provided you with a /29 subnet of public IP adresses.
You should have 6 IP adresses, subnet mask and also a gateway for your network. The default gateway is the IP address of the port on ISP's router.
I guess one of IPs is being used on external ASA interface and you should have no problems connecting another device on external cisco switch using another IP address.
You can do a simple test. Just configure a laptop with a available public IP, subnet mask, gateway (check GW defined on external ASA interface) and DNS servers and try if you can browse the internet. Most likely browsing will work and that means that you don't need another router.
0
 

Author Comment

by:philb19
Comment Utility
check GW defined on external ASA interface) ??
thanks - helpul but I checked and there is no gateway set on any interface of the ASA

just default route 0.0.0.0 - to ISP IP address - SO if i set the gateway to the ISP IP - i should be right?
0
 

Author Comment

by:philb19
Comment Utility
sorry you right - static routes shows gateway of next hop - thanks for answering - simple answer :)
0

Featured Post

New My Cloud Pro Series - organize everything!

With space to keep virtually everything, the My Cloud Pro Series offers your team the network storage to edit, save and share production files from anywhere with an internet connection. Compatible with both Mac and PC, you're able to protect your content regardless of OS.

Join & Write a Comment

Let’s list some of the technologies that enable smooth teleworking. 
If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now