Ok.. Good day, I have an ASA 5510 and a 2921 -
My ASA is used for VPN and Internet
My 2921 is used to connect different subnets
I also have an attached diagram
I have a directly connected interface on 2921-10.10.10.1 to the ASA 10.10.10.2
Also on the 2921 i have a subnet 192.168.2.0 and 10.20.30.0
I have trunk link on my switch 2950 from the 2921... The ASA is aslo connected to the switch
on the ASA
Int0/0 66.xxx.xxx.xxx internet
Int0/1 10.20.60.2 - Gateway for computers
Int0/2 10.10.10.2 - connected to 2921
on the 2921
gig0/1 10.10.10.1 - connected to ASA
gig0/1.20 sub-if 192.168.2.1
gig0/1.30 sub-if 10.20.30.1
I have connected some static routes to get from 10.20.60.0 to 192.168.2.0
I cannot ping 10.10.10.2 from my PC
I cannot ping 10.20.60.2 from my 2921
I would appreciate any ideas for configuration help... And redesign...
What cannot happen is for us to use the 2921 for vpn and internet..
Thanks,,, see image.
I think the way you have it now is the way to do it ie. use the 2921 to route the internal vlans and only use the ASA when you need to go to the internet or use the vpn. If you wanted to use the ASA to route the vlans then you would need additional configuration on it and i can't see the advantage of doing that unless you have security issues ?
Does this make sense ?