Solved

Cisco help

Posted on 2016-08-04
4
37 Views
Last Modified: 2016-08-04
I  have an old Cisco 3825 router that I am replacing with ASA 5525x Firepower IPS and ISR 4431 router. My old router has 2 outside interfaces (handoffs) that bandwidth comes in from COLO and 1 interface that is a cross connect to my circuits. The old router is running the following roles/protocols: VPN (few different flavors dynamic and isakmp client), BGP, DHCP for voip/users, with some extended access lists. The question is, do I use 2 outside IPs that were previously on my router outside interfaces on the 2 outside ASA interfaces since it will be in front of the router facing the handoffs, then use the inside interfaces to connect to 2 router internal IPs interfaces?
0
Comment
Question by:yachtingpromotions
  • 2
  • 2
4 Comments
 
LVL 3

Expert Comment

by:Steven Roman
ID: 41742842
Hello


I would put a External Switch to handle the external ports first off just to make it easier to monitor and function
Yo mention one external to Colo and one for cross connects circuits(what kind of circuits) ISP, Wan, telco etc?

The ASA Firepower can do the Procider connections, DHCP for internal and ACLs, but I would recommend something internal do DHCP for Coice/Users like an internal Server or Switch.  Heck you can has the ASA do all th eBorder work and use the Router as an internal Routing/Gwateway function

What BGP is running?  Multi ISp connections?  VPN connections can be done on the ASA also
0
 

Author Comment

by:yachtingpromotions
ID: 41742878
I really don't want to buy another piece of equipment as far as outside switch goes, just want to plug the 2 handoffs from ISP with external static IPs into ASA and take it from there. The circuits are fiber metro E, that connect to 2 locations of of the company.  Is it better to handle DHCP on ASA or Router since I have both, never liked server DHCP. The BGP is same provider, 2 separate handoffs. VPN is a must on ASA, that I know now.
0
 
LVL 3

Accepted Solution

by:
Steven Roman earned 500 total points
ID: 41742927
Hi,

No worries you can forego th eExt Switch

If the same ISP gives both Links are they going in via Fiber to a Metro switch then Copper to you?
If so you can have both go into your ASA.  In the ASA you can set Tracking to monitor one interface and if it fails send traffic out the other one.

But if th eISP is doing anything with BGP the ASA cannot do BGP and you have to use th eRouter and burn it up ofr this simple process.


I would talk to the ISP and ask them if you can just add default routes out both paths and track on the ASA.  This would free up the router

Thanks
0
 

Author Closing Comment

by:yachtingpromotions
ID: 41742936
Thank you! This has pointed me in the right direction, I will get started on the config.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now