05-15-2012 03:43 AM - edited 03-11-2019 04:07 PM
Hi I'm trying to install an ASA 5510 transparent firewall using ASA version 8.4(3)9 but I dont understand how traffic will ever pass through my firewall if both interfaces are on the same subnet(Vlan) as the host and it's default gateway?
The reason im doing this is were installing UAG (or Direct Access) and the UAG appliance need to have public IP's but still be behind a firewall (see attached diagram)
Looking at the documentation (which all seems to be for 5505's running 8.2) it almost seems like i need to have the transparent firewall 'in-line' to the ISP router?, but this router services another IP address range on another vlan for other (routed) firewalls (not shown on diagram) so putting it 'in-line' is not possible. Surely this can't be the case can it? If not how is it supposed to be cabled up and configured so packets go through the firewall? Thanks.
05-15-2012 09:36 AM
Hello,
Please add the diagram...
Regards,
Julio
05-16-2012 01:39 AM
05-16-2012 11:21 AM
Hello,
Yeah, the thing is that in order to have the ASA on transparent mode the requirement is that you cannot split the network with it, so both interfaces will need to be on the same broadcast domain.
Just remember that you can still do nat for the UAG Appliance if need it
Regards,
Let me know if I there is something else I can do for you
Julio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide