Link to home
Start Free TrialLog in
Avatar of Jennifer
JenniferFlag for United States of America

asked on

Switch routing on Procurve to ASA

I have inherited a project that I need to update. I have an HP Procurve 2848 switch. I have two routers. I have three offices. It was setup in the Switch to route the two branch locations to the second router and not through the ASA. There is only one VLan on the switch. I will be disconnecting the second router. I need to point the ip routes in the switch to the ASA.

Here is my ip route in the switch
  Destination              Gateway               VLAN Type            Sub-Type         Metric           Dist.
                              
  0.0.0.0/0                172.16.4.1            1      static      1      1
  127.0.0.0/8             reject                     static       0      250
  127.0.0.1/32            lo0                              connected       0      0
  172.16.4.0/24            DEFAULT_VLAN   1      connected       0      0
  172.16.17.0/24     172.16.4.3           1      static       1      1
  172.16.19.0/24     172.16.4.3           1      static       1      1

I believe I can just remove the ip route but want to verify what steps to take.

My next question would be what changes do I need to make to the ASA to make sure it recognizes these routes? I believe I need to create these as site to site tunnel but would still need to add them to the access list.

Any help would be greatly appreciated!
Avatar of Schuyler Dorsey
Schuyler Dorsey
Flag of United States of America image

If  you are changing the routes to point to the ASA, the ASA would need static routes added to it for the return traffic.

As far as the site to site question, so are you asking about creating a NEW site to site tunnel to site B?
Avatar of Jennifer

ASKER

Yes, the first thing I need is to change the switch to move the 172.16.17.0/24 and 172.16.19.0/24 from 172.16.4.3 to the internal default gateway. Just as the 172.16.4.0/24 is in the above post. The 172.16.4.3 router is going to be disconnected 4/7/2014.

I have created a site to site tunnel in the ASA 5510, I used the GUI wizard, for both of these subnets. I have inside-outside NAT rules now. User generated image Do I need outside-inside?
I have a Site to Site connection profile for each as well. User generated image Are the local/remote the right direction?
Do I need to have Access Rules?

I have added a second VPN tunnel in their routers to point to our new external gateway versus the old. I would only need to disable one and enable the other.

Do I need to have their ISP's internet and gateway IP's in my ASA?

I am sorry for all of the questions. I think I know how to do these but having not worked with them enough I would rather confirm. These changes will bring down my branch offices if not done right.

Thanks for all of the help!
ASKER CERTIFIED SOLUTION
Avatar of Schuyler Dorsey
Schuyler Dorsey
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thank you so much. I am still having a problem getting my remote offices changed in my switch. Do I need to re-add them with the 4.1 or will the 0.0.0.0 0.0.0.0 172.16.4.1 existing route take care of them?

User generated image
Do I need to leave spanning-tree enabled?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I did use the VPN site to site wizard. The first time I had put the IP address of the router versus the IP address of the remote ISP so after your response I went in and changed.

I did remove the static route for that location from the switch and left it to use the default, which is what I needed.

Moved the first branch office this morning, minor hiccup but that was a typo, otherwise went great. They are now on a 100mg vs. 3mg tunnel.

THANK YOU SO MUCH FOR THE HELP.