Solved

Cisco help

Posted on 2016-08-04
4
49 Views
Last Modified: 2016-08-04
I  have an old Cisco 3825 router that I am replacing with ASA 5525x Firepower IPS and ISR 4431 router. My old router has 2 outside interfaces (handoffs) that bandwidth comes in from COLO and 1 interface that is a cross connect to my circuits. The old router is running the following roles/protocols: VPN (few different flavors dynamic and isakmp client), BGP, DHCP for voip/users, with some extended access lists. The question is, do I use 2 outside IPs that were previously on my router outside interfaces on the 2 outside ASA interfaces since it will be in front of the router facing the handoffs, then use the inside interfaces to connect to 2 router internal IPs interfaces?
0
Comment
Question by:yachtingpromotions
  • 2
  • 2
4 Comments
 
LVL 4

Expert Comment

by:Steven Roman
ID: 41742842
Hello


I would put a External Switch to handle the external ports first off just to make it easier to monitor and function
Yo mention one external to Colo and one for cross connects circuits(what kind of circuits) ISP, Wan, telco etc?

The ASA Firepower can do the Procider connections, DHCP for internal and ACLs, but I would recommend something internal do DHCP for Coice/Users like an internal Server or Switch.  Heck you can has the ASA do all th eBorder work and use the Router as an internal Routing/Gwateway function

What BGP is running?  Multi ISp connections?  VPN connections can be done on the ASA also
0
 

Author Comment

by:yachtingpromotions
ID: 41742878
I really don't want to buy another piece of equipment as far as outside switch goes, just want to plug the 2 handoffs from ISP with external static IPs into ASA and take it from there. The circuits are fiber metro E, that connect to 2 locations of of the company.  Is it better to handle DHCP on ASA or Router since I have both, never liked server DHCP. The BGP is same provider, 2 separate handoffs. VPN is a must on ASA, that I know now.
0
 
LVL 4

Accepted Solution

by:
Steven Roman earned 500 total points
ID: 41742927
Hi,

No worries you can forego th eExt Switch

If the same ISP gives both Links are they going in via Fiber to a Metro switch then Copper to you?
If so you can have both go into your ASA.  In the ASA you can set Tracking to monitor one interface and if it fails send traffic out the other one.

But if th eISP is doing anything with BGP the ASA cannot do BGP and you have to use th eRouter and burn it up ofr this simple process.


I would talk to the ISP and ask them if you can just add default routes out both paths and track on the ASA.  This would free up the router

Thanks
0
 

Author Closing Comment

by:yachtingpromotions
ID: 41742936
Thank you! This has pointed me in the right direction, I will get started on the config.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question