Jennifer
asked on
Switch routing on Procurve to ASA
I have inherited a project that I need to update. I have an HP Procurve 2848 switch. I have two routers. I have three offices. It was setup in the Switch to route the two branch locations to the second router and not through the ASA. There is only one VLan on the switch. I will be disconnecting the second router. I need to point the ip routes in the switch to the ASA.
Here is my ip route in the switch
Destination Gateway VLAN Type Sub-Type Metric Dist.
0.0.0.0/0 172.16.4.1 1 static 1 1
127.0.0.0/8 reject static 0 250
127.0.0.1/32 lo0 connected 0 0
172.16.4.0/24 DEFAULT_VLAN 1 connected 0 0
172.16.17.0/24 172.16.4.3 1 static 1 1
172.16.19.0/24 172.16.4.3 1 static 1 1
I believe I can just remove the ip route but want to verify what steps to take.
My next question would be what changes do I need to make to the ASA to make sure it recognizes these routes? I believe I need to create these as site to site tunnel but would still need to add them to the access list.
Any help would be greatly appreciated!
Here is my ip route in the switch
Destination Gateway VLAN Type Sub-Type Metric Dist.
0.0.0.0/0 172.16.4.1 1 static 1 1
127.0.0.0/8 reject static 0 250
127.0.0.1/32 lo0 connected 0 0
172.16.4.0/24 DEFAULT_VLAN 1 connected 0 0
172.16.17.0/24 172.16.4.3 1 static 1 1
172.16.19.0/24 172.16.4.3 1 static 1 1
I believe I can just remove the ip route but want to verify what steps to take.
My next question would be what changes do I need to make to the ASA to make sure it recognizes these routes? I believe I need to create these as site to site tunnel but would still need to add them to the access list.
Any help would be greatly appreciated!
ASKER
Yes, the first thing I need is to change the switch to move the 172.16.17.0/24 and 172.16.19.0/24 from 172.16.4.3 to the internal default gateway. Just as the 172.16.4.0/24 is in the above post. The 172.16.4.3 router is going to be disconnected 4/7/2014.
I have created a site to site tunnel in the ASA 5510, I used the GUI wizard, for both of these subnets. I have inside-outside NAT rules now. Do I need outside-inside?
I have a Site to Site connection profile for each as well. Are the local/remote the right direction?
Do I need to have Access Rules?
I have added a second VPN tunnel in their routers to point to our new external gateway versus the old. I would only need to disable one and enable the other.
Do I need to have their ISP's internet and gateway IP's in my ASA?
I am sorry for all of the questions. I think I know how to do these but having not worked with them enough I would rather confirm. These changes will bring down my branch offices if not done right.
Thanks for all of the help!
I have created a site to site tunnel in the ASA 5510, I used the GUI wizard, for both of these subnets. I have inside-outside NAT rules now. Do I need outside-inside?
I have a Site to Site connection profile for each as well. Are the local/remote the right direction?
Do I need to have Access Rules?
I have added a second VPN tunnel in their routers to point to our new external gateway versus the old. I would only need to disable one and enable the other.
Do I need to have their ISP's internet and gateway IP's in my ASA?
I am sorry for all of the questions. I think I know how to do these but having not worked with them enough I would rather confirm. These changes will bring down my branch offices if not done right.
Thanks for all of the help!
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
I did use the VPN site to site wizard. The first time I had put the IP address of the router versus the IP address of the remote ISP so after your response I went in and changed.
I did remove the static route for that location from the switch and left it to use the default, which is what I needed.
Moved the first branch office this morning, minor hiccup but that was a typo, otherwise went great. They are now on a 100mg vs. 3mg tunnel.
THANK YOU SO MUCH FOR THE HELP.
I did remove the static route for that location from the switch and left it to use the default, which is what I needed.
Moved the first branch office this morning, minor hiccup but that was a typo, otherwise went great. They are now on a 100mg vs. 3mg tunnel.
THANK YOU SO MUCH FOR THE HELP.
As far as the site to site question, so are you asking about creating a NEW site to site tunnel to site B?