troubleshooting Question

VRF, OSPF Routing and Firewall Help Request

Avatar of daryldavies
daryldavies asked on
RoutersSwitches / HubsCisco
10 Comments1 Solution781 ViewsLast Modified:
I have a Cisco network with Cisco 4948 switch, 3800 router, and ASA5520 firewall.

I would like to build all my SVI's on the Cisco 4948 switch and do internal routing on the 4948 switch. Would like to build several VRF's per network and utilize ospf to route traffic to the firewall in order for traffic to be filtered.

Would like to use the router only for external routing and would still want these traffic to traverse the firewall.

I have the following two network for testing:

Network 1 - 10.10.10.0/28 - WEB NETWORK  (TEST SERVER 10.10.10.8)
Network 2 - 10.10.11.0/28-APP_DB NETWORK    (TEST SERVER 10.10.11.8)

I tried a telnet from 10.10.10.8 to 10.10.11.8 on port TCP139 and no answer.

SEE CONFIG BELOW:

!
****** CIS4948 **********
!
vlan 255
name WEB
!
!
vlan 256
name APP_DB
!
ip vrf WEB
 description WEB VRF
 rd 1:255
!
!
!
!
ip vrf APP_DB
 description APP_DB VRF
 rd 1:256
!
!
interface Vlan255
 description WEB Subnet
 ip vrf forwarding WEB
 ip address 10.10.10.2 255.255.255.240
 no ip redirects
 no ip proxy-arp
 standby 1 ip 10.10.10.1
 standby 1 priority 110
 standby 1 preempt
!
!
!
interface Vlan256
 description APP_DB Subnet
 ip vrf forwarding APP_DB
 ip address 10.10.11.2 255.255.255.240
 no ip redirects
 no ip proxy-arp
 standby 1 ip 10.10.11.1
 standby 1 priority 110
 standby 1 preempt
!
!
router ospf 11 vrf WEB
 router-id 10.10.12.5
 log-adjacency-changes
 auto-cost reference-bandwidth 100000
 capability vrf-lite
 area 16 nssa
 passive-interface Vlan255
 network 10.10.10.0 0.0.0.15 area 16
!
!
!
router ospf 12 vrf APP_DB
 router-id 10.10.12.5
 log-adjacency-changes
 auto-cost reference-bandwidth 100000
 capability vrf-lite
 area 16 nssa
 passive-interface Vlan256
 network 10.10.11.0 0.0.0.15 area 16
!
!
!
!
****** CIS5520 **********


interface vlan

!
interface GI0/1.255
 description WEB
 vlan 255
 nameif WEB#255
 security-level 61
 ip address 10.10.10.4 255.255.255.240
 ospf cost 1
 ospf priority 2
!
!
!
interface GI0/1.256
 description APP_DB
 vlan 256
 nameif APP_DB#256
 security-level 61
 ip address 10.10.11.4
 ospf cost 1
 ospf priority 2
!
!
object-group service WEB_PORT
description WEBPORT
service-object tcp 80
service-object tcp 8080
!
!
object-group service WEB_PORT
description WEBPORT
service-object tcp 8442
service-object tcp 443
service-object tcp 22
!
!
object-group network WEB
description WEB
network-object 10.10.10.0 255.255.255.240
!
object-group network APP_DB
description APP_DB
network-object 10.10.11.0 255.255.255.240
!
!
!
object-group service DB_PORT
 description DB_PORT
 service-object icmp6 echo
 service-object icmp6 echo-reply
 service-object tcp eq 445
 service-object tcp eq 8080
 service-object tcp eq https
 service-object tcp eq netbios-ssn
!
!
!
object-group service WEB_PORT
 description WEBPORT
 service-object tcp eq www
 service-object tcp eq 8442
 service-object tcp eq ssh
 service-object tcp eq 8080
 service-object tcp eq https
!
access-list WEB#255_access_in extended permit object-group DB_PORT object-group WEB object-group APP_DB
access-list APP_DB#256_access_in extended permit object-group WEB_PORT 10.0.0.0 255.0.0.0 10.10.10.0 255.255.255.240
!
!
router ospf 11
network 10.10.10.0 255.255.255.255 area 16
area 16 nssa
router-id 10.10.10.5
log-adj-changes
!
!
router ospf 12
network 10.10.11.0 255.255.255.255 area 16
area 16 nssa
router-id 10.10.11.5
log-adj-changes
!
ASKER CERTIFIED SOLUTION
keakathleen

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 10 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 10 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros