cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
741
Views
3
Helpful
6
Replies

Different Public IP Range into Firewall

b.petronio
Level 3
Level 3

Hi,

Sorry if it is not the best place to this thread.

I have one client with the Public IP Address range for their WebServers:

aaa.bbb.141.112 /28

They ask for more 16 ip's to the provider, and it was given the following range:

aaa.bbb.140.112 /28

I had configured in the internet router, one vrf called internet, wich has Vlan5 associated and therefore logicaly attached to the firewall, trhougt a switch.

There is a NAT configured in the FireWall, translating the public ip address's, (webserver, mail, dns, etc..), into private one's.

This was working just fine with one network only.

Then the client was the need to implement another web services and ask for the provider another range of ip's.

** PROBLEM: **

The issue is that i configure the new network as a secondary in the same Vlan5, and i cant just access nothing in the Firewall.

The "show ip route vrf internet" see the new network in the vlan5, where i have the Firewall.

I have a Packteer between the Firewall and the router, and change the ip to the new range and works fine, but not reaching the new ip range, into the FireWall. (nothing reaches the FireWall log)

I think that i have to add a new network address in the Firewall, but i cant do it in the same NIC and have no more free NIC's.

If i buy another NIC card an configure the new address range, can i connect this in the same switch, i dont know if it will work fine in the same switch it is connected the existing one (2 networks ? in the same switch).

The G1/0/20, is configured with "switchport access vlan 5" command.

I tought to put it as a trunk , in both sides (router and swith) and make another vlan with the new range, but i think that have the same problem with the FireWall.

Do u have any another sugestions to do this ?

Even if it need to change this network topology.

Best regards,

Petr?nio

6 Replies 6

b.petronio
Level 3
Level 3

I did a static route host by host, to the FW address.

The sub-network address dont work.

Maybe a bug.

Petr?nio

jvulto
Level 1
Level 1

Hello there,

Do you have a drawing available in which you explain your issue?

As I understand now you configure two IP address ranges at the Router interface. This is from switching point of view no problem. You just have one broadcast domain VLAN5 with two IP subnets defined in it. Your firewall however only has an IP address in the first IP range so you have no ip connectivity at this stage. Creating a second interface at the Firewall and connecting that one into the VLAN5 is a possibility. However I would say that you try to configure a trunk for both the firewall AND the router and define a new VLAN so traffic is not mixed into the same broadcast domain.

regards,

Jos

After studying your drawing I found my previous reply still is ok. Another option could of course be to have a new separate interface configured at your Firewall into the new subnet. Also make sure you configure routing as needed if you do not use NAT in the same IP range.

regards,

Jos

Tks Jos,

The client has no more free NIC slot's in the CheckPoint FW and as i couldn't figured out a way to configure a second range ip address.

If i found a way from doing that, i would done the trunk issue.

Now its working with a ip route vrf "new host" 255.255.255.255 "ip Fw"

When i try to do ip route vrf "new range" 255.255.255.240 "ip Fw", it simple doesnt work.

aaa.bbb.141.0/24 is variably subnetted, 2 subnets, 2 masks

C aaa.bbb.141.112/28 is directly connected, Vlan5

S aaa.bbb8.141.118/32 [1/0] via aaa.bbb.140.126

Drawn Correction: IP Firewall is aaa.bbb.140.126

Workaround, not a solucion, but im happy :)

Petr?nio

jvulto
Level 1
Level 1

Sorry, found your drawing :(

Nevertheless, what is the best practise to implement various public ip range address into a private network.

I found this scheme in this client, dont know if the best one.

Tks

Petr?nio

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card