This network in blue has been a reoccurring pattern over the last few years and I want to put forward the simple premise: Use the ASA by itself instead of putting a slow router in front of it. Let me be clear there are perfect reasons to have a router in front, such as if you are running BGP to route the subnet you have, or to have another layer of control. My point here is don't put a slow router in front of a faster firewall and don't start asking your boss to buy an expensive fast router just to add another hop...
We are a small group of technical people with common interests that want to share and post our thoughts and opinions of our everyday experiences with technologies. A few of us decided that writing our thoughts down will help us to understand the technologies we use a little better.
Showing posts with label Cisco ASA. Show all posts
Showing posts with label Cisco ASA. Show all posts
Wednesday, October 10, 2012
Multiple Subnets on the Outside Interface of a Cisco ASA
Recently I had a customer provide a Cisco 2821 router along with a Cisco ASA 5520 to setup at a DR site. The router was provided in case the ISP provided a small subnet for connecting the router to the ISP's equipment (usually a /29 or /30), and also gave another subnet that would provide the functional IP space for the customer's equipment (something like a /24).
This network in blue has been a reoccurring pattern over the last few years and I want to put forward the simple premise: Use the ASA by itself instead of putting a slow router in front of it. Let me be clear there are perfect reasons to have a router in front, such as if you are running BGP to route the subnet you have, or to have another layer of control. My point here is don't put a slow router in front of a faster firewall and don't start asking your boss to buy an expensive fast router just to add another hop...
This network in blue has been a reoccurring pattern over the last few years and I want to put forward the simple premise: Use the ASA by itself instead of putting a slow router in front of it. Let me be clear there are perfect reasons to have a router in front, such as if you are running BGP to route the subnet you have, or to have another layer of control. My point here is don't put a slow router in front of a faster firewall and don't start asking your boss to buy an expensive fast router just to add another hop...
Subscribe to:
Posts (Atom)
