cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
545
Views
0
Helpful
8
Replies

Adding a second public subnet to an ASA 5510

tahequivoice
Level 2
Level 2

I have a customer who needs more address space, and instead of readdressing everything on the ASA, is it possible to use the fourth ethernet port as a second public interface to the internet? Both interfaces will terminate onto a 2610 through a switch with the second subnet as secondary on the e0/0 port. Name it outside2 with security 0, and have the static nat statements for the internal servers in that subnet?

1 Accepted Solution

Accepted Solutions

acomiskey
Level 10
Level 10

It's not necessary to use another interface, just make sure the isp routes the new subnet to your ASA, write the statics and you'll be good to go.

View solution in original post

8 Replies 8

acomiskey
Level 10
Level 10

It's not necessary to use another interface, just make sure the isp routes the new subnet to your ASA, write the statics and you'll be good to go.

heheh I'm the ISP! :) So if I just add static translations in the new range, and have the gateway address on the router as secondary, I should be able to route through to them?

Well it should be a piece of cake then, haha. Yes, that should be fine.

OK, I am going to lab test it now with another 5510 I have just finished with for another customer. I'll get back to ya.

Well, I can see the arp entry, but I am not able to ping the machine. I have an ACL that allows all traffic through to the box.

Hello tahequivoice, if You`re an ISP ;) can I ask You to take a look on the post in the link below ? maybe You can give me an answer ?

I am having big problems to find a solution on my question. Since this is forum category for FIREWALLING, I will not post the question here, but just the link:

http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Network%20Infrastructure&topic=LAN%2C%20Switching%20and%20Routing&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddeb9aa

It will not take a long time for You to read trough the messages ok ?

And if someone of You other boys who replied to tahequivoice know the solution, so please help !! Help this poor soul, I was looking for this solution long time, without success.

Thank you !!

Best regards

James

I replied to your question, hopefully it is what you are seeking.

Confirmed. The reason it didnt work the first time was I fat fingered the inside IP, the second test I found it needs to be directly connected to the router so it picks up the ARP entry. I had it running through a Vlan in the first.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card