11-07-2011 11:41 AM - edited 03-11-2019 02:47 PM
I recently installed a 2951 with a security plus license..I hate it (security featuers not router) and would like to put the asa back in place.
I need some direction on how to integrate the asa with the 2951, I believe I need to run it in multi context mode.
in a nut shell I have this
isp--->router (firewall, VPN, voice, & vLANS) --->switches
I would like this
isp --->ASA (firewall, VPN) ---->router (vLans)--->switches
where do I start..what issues will I run into.
11-07-2011 12:41 PM
Should be as simple as putting a small transport network between the ASA and the router. Set default gateway on router to ASA IP, add routes in ASA for inside networks towards router IP, or use a routing protocol between the 2.
isp -->ASA-(x.x.x.1)----->(x.x.x.2)router (vlans) ---> switches
Definitely don't need multi context.
ASA
route inside
route isnide
Router
ip route 0.0.0.0 0.0.0.0 x.x.x.1
11-07-2011 12:51 PM
What about NAT?
Would NAT translation take place on the ASA or Router in your proposed setup?
11-07-2011 12:53 PM
ASA
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: