Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Transparent Firewall (ASA 5510 ver8.4)

Hi I'm trying to install an ASA 5510 transparent firewall using ASA version 8.4(3)9 but I dont understand how traffic will ever pass through my firewall if both interfaces are on the same subnet(Vlan) as the host and it's default gateway?

The reason im doing this is were installing UAG (or Direct Access) and the UAG appliance need to have public IP's but still be behind a firewall (see attached diagram)

Looking at the documentation (which all seems to be for 5505's running 8.2) it almost seems like i need to have the transparent firewall 'in-line' to the ISP router?, but this router services another IP address range on another vlan for other (routed) firewalls (not shown on diagram) so putting it 'in-line' is not possible. Surely this can't be the case can it? If not how is it supposed to be cabled up and configured so packets go through the firewall? Thanks.

3 REPLIES

Transparent Firewall (ASA 5510 ver8.4)

Hello,

Please add the diagram...

Regards,

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Community Member

Re: Transparent Firewall (ASA 5510 ver8.4)

Re: Transparent Firewall (ASA 5510 ver8.4)

Hello,

Yeah, the thing is that in order to have the ASA on transparent mode the requirement is that you cannot split the network with it, so both interfaces will need to be on the same broadcast domain.

Just remember that you can still do nat for the UAG Appliance if need it

Regards,

Let me know if I there is something else I can do for you

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
374
Views
0
Helpful
3
Replies
CreatePlease to create content