Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Cisco ASA5512x and ADTRAN 838T modem.  Configuration question.

Posted on 2014-09-16
4
Medium Priority
?
598 Views
Last Modified: 2014-09-21
Greetings.  I am relatively new to routing, so this might be simple.

We have a 40Mb/s Ethernet over Copper (EoC) circuit.  This is essentially high speed DSL.

Our circuit goes into an ADTRAN 838T Modem running in "bridged" mode.

Out of the ADTRAN, an Ethernet cable goes into a small business (what I would term "consumer") router, a Cisco WRV210.  This router has the "WAN" setup configured per our ISP.

The "LAN" side of the router (WRV210) has our /29 network plugged in (local IP of the router and 255.255.255.248 mask).

The "LAN" side of the router (WRV210) connects via Ethernet cable to our "outside" interface of our Cisco ASA5512x firewall/router.

We were told by the ISP that since the ADTRAN runs in "bridged" mode, that a router was necessary between it and our network.

We were told by our IT consultant that we could not simply connect the ADTRAN to the ASA5512x.

So .... I am curious why a Cisco ASA5512x cannot have a bridged ADTRAN 838T connected to it and router that network from one interface to another interface.  Maybe it's obvious to the experts, but not to me.

Also, it looks like the WRV210 is more of a "consumer" router (it has wireless, is plastic, and weights all of 8 ounces or so). Looking at the "System Up Time" on the WRV210 today (just at random), it showed 1 hour 46 minutes.  That doesn't inspire confidence.  Also, every so often the "Outside" Gig Interface on the ASA simply goes "down", then "up" again.  I suspect the WRV210 is not overly reliable.  Finally, we're considering a VoIP solution early next year, so I'm wondering if I want all our network traffic, including VoIP, going through this $150 consumer router.

Suggestions ?
Thanks much.
-Stephen
0
Comment
Question by:lapavoni
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 57

Accepted Solution

by:
giltjr earned 2000 total points
ID: 40328080
Since the Adtran is running in bridged mode you can think of it as a switch.  That is what a bridge basically is.

The only reason I can think of why an ASA could not directly connect to the Adtran is if you are running the ASA in bridge mode instead of routed mode.  If you are running the ASA in routed mode, which is the mode I would assume most people run it, then there should be no problems connected the Adtran directly to it.  It would be like connecting any other switch to the ASA.

If you are running the ASA in bridge mode, then you would need another device acting as a router between your "network" and the Adtran.  This means that the router could be connected on either side of the ASA (inside or outside), it just depends on where you may want it.

Your ISP is correct, you do need a "router" between your network and the Adtran, however when running the ASA in routed mode, it is the router.
0
 

Author Comment

by:lapavoni
ID: 40329412
The ASA is running in routed mode (vs. "transparent" ... Cisco's terminology for bridged).

The cheap router has a "WAN" address I presume what is the ADTRAN's address, but the "LAN" address is not our internal network.  It is our external-facing /29 network address.  We have a pool of 4 available IPs.  We use two of them (one for our mail server - NATed internally, and one for our VPN connection, which is essentially our "outside" interface address).
0
 
LVL 57

Expert Comment

by:giltjr
ID: 40329513
I am assuming that you are doing the NAT on the cheap router.

You should be able to remove the cheap router and configure one of the interfaces on the ASA with the same public IP address as the cheap router, and to the NAT'ing on the ASA.
0
 

Author Closing Comment

by:lapavoni
ID: 40335510
I'm still investigating permanent solution, but this is useful information. Thank you.
0

Featured Post

ATEN's HDBaseT Presentation at InfoComm 2017

Hear ATEN Product Manager YT Liang review HDBaseT technology, highlighting ATEN’s latest solutions as they relate to real-world applications during her presentation at the HDBaseT booth at InfoComm 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
Make the most of your online learning experience.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Suggested Courses

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question