Network routing issue.

Hello all,
Thank you for taking the time to look at this question.

I have just inherited a network that looks to have more then a few band-aids on it. As I try to wrap my mind around it I get a little cross-eyed and I think that's because more then a few hands from different agencies (who did not communicate) put it together.    I have the ability to make some limited changes but management is key to keep/incorporate a few features that I am running into an issue with.

The problem comes down to the 'Untangle' security appliance. Without it in place everything is working fine, When I have it in place I loose connection between the 10.1.28.x and 192.168.1.x networks.

In the included network diagram:

- The Main office,  Top Box - 10.1.28.x network.  The edge router is an ASA 5505.  The internal network looks to this device as the gateway and, as I understand it, all traffic destine for another network hits that edge router first.  This ASA includes a few route / bypass statements to redirect all traffic to and from the 192 network. Which works fine without the introduction of the Untangle security appliance.  

- Management likes the features of the untangle and insist I keep it.

- When I introduce the untangle it looks as if it lets the traffic destine for the 192 network thru to the ASA but does not allow it back thru to the ISP managed equipment.   I've worked with UNTANGLE to redirect/ ignore or allow all the 192 traffic to pass but they were unable to assist me.

- The current suggestions from my piers is to insert a managed switch before the untangle that routes all 192. traffic before it gets to the untangle or ASA.

* Is that the best course of action or is there another solution?  
* If it is the best course of action, is there a recommendation on the type of managed switch I should use?

- I was wondering if there was a way to set up a connection between the ASA and the ISP managed equipment with a direct line, perhaps as another VPN.   This occurs to me as the untagle has no issues with the traffic from the remote office thru the VPN on the 10.1.27.x network.

Thank you in advance.  
I apologize in advance if any of my vernacular is off.


Jonathan JoyeNetwork ConsultantAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Let's ask this, since management seems to be so keen on keeping Untangle: What changed to cause things to stop working in the first place? Also, what exactly are you utilizing Untangle for?
Jonathan JoyeNetwork ConsultantAuthor Commented:
the untangle is new, its replacing some a set of web and spam barracuda's.    As it is hey like it, and want it to stay. So my job is to now integrate it.
- management prefers the interface and reporting of the untangle device.
- it is being used to monitor traffic inside and outside the network.
Did some research, and it's actually been an issue for several years. To so answer your question in terms of whether or not to use the managed switch, the answer is yes. Since it appears that your infrastructure is primarily Cisco, then I'd just use a Cisco managed switch. (Not getting into specific models because the right answer is usually based on organization size)

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Jonathan JoyeNetwork ConsultantAuthor Commented:
Thank you for your answer
Jonathan JoyeNetwork ConsultantAuthor Commented:
Thank you for your time.  I will get with Cisco to determine the switch model I need.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.