09-30-2008 06:26 AM - last edited on 03-25-2019 03:20 PM by ciscomoderator
Greetings, ive been wrestling with this for awhile now.
We have an MPLS link presented on ethernet comming into the premises, the link is configured as a 802.1q trunk with two vlans, one for a link into the MPLS cloud lets call it vlan 10 and one vlan which will provide an internet services for the business lets call it vlan 20. A /28 public address block has been allocated for internet access.
The ethernet link terminates on a Cisco 3825 ISR with a 4 Port ethernet Hwic installed.
What i would like to do is bridge the internet vlan onto the outside interface of an ASA 5510 then back onto the router so that internal users can access both internet resources and the mpls network on a common gateway.
Is this possible with the current hardware setup?
Regards
Solved! Go to Solution.
10-01-2008 01:35 AM
Hello Mark,
the MPLS link can be terminated on a L2 trunk with vlan 10 and vlan 20 configured on one of the ports of the 4 FE HWIC.
A second port is an access port for vlan 20 and connects to ASA.
The trick is to use a third vlan : vlan 30 for the second interface of the ASA that will be bridging between vlan 20 and vlan 30 and inspecting traffic
So the third port will be in vlan 30.
At layer 3 you will define only an address for vlan 30 in the internet access network
So I think it should be possible to achieve what you want to do
Hope to help
Giuseppe
10-01-2008 01:35 AM
Hello Mark,
the MPLS link can be terminated on a L2 trunk with vlan 10 and vlan 20 configured on one of the ports of the 4 FE HWIC.
A second port is an access port for vlan 20 and connects to ASA.
The trick is to use a third vlan : vlan 30 for the second interface of the ASA that will be bridging between vlan 20 and vlan 30 and inspecting traffic
So the third port will be in vlan 30.
At layer 3 you will define only an address for vlan 30 in the internet access network
So I think it should be possible to achieve what you want to do
Hope to help
Giuseppe
10-01-2008 04:35 AM
Thank you for the reply Giuseppe it makes perfect sense, i was having somewhat of a mind block. I was working under the premise that the trunk had to be terminated on the routed interface on an ISR and didnt actually think of terminating it on the HWIC.
Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide