<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Edge Router connection for Outside Interface of ASA 5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/edge-router-connection-for-outside-interface-of-asa-5520/m-p/2209116#M350664</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If what you are saying is that you have a ISP router facing your ASA "outside" interface and that ISP Router interface that is facing your ASA holds the network 198.24.210.224/29 then there should be no problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is will route that whole network in their ISP Core and advertise it so traffic destined to any of those IP addresses from that netwokr 198.24.210.224/29 will reach the ISP Router/ASA wether you are using the single IP address in question or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess we were already discussing this same thing on another topic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you still having problems with reaching other IP addresses from the subnet? I would ask the ISP to confirm the configuration on their side and confirm that they can see the ARP for the public IP address that is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 May 2013 15:55:36 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-05-02T15:55:36Z</dc:date>
    <item>
      <title>Edge Router connection for Outside Interface of ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/edge-router-connection-for-outside-interface-of-asa-5520/m-p/2209115#M350663</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have ASA 5520 firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For broadband Internet access, we have T1 Router(edge router provided by ISP) which provides public IP's 198.24.210.224/29.&lt;/P&gt;&lt;P&gt;We have usable public IP's 198.24.210.226 - 198.24.210.230 with default gateway 198.24.210.225.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We assigned 198.24.210.230 255.255.255.0 to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we connect the ASA 5520 outside interface directly to T1 router, can all packets with destination addresses 198.24.210.224/29 reach the outside interface without using other device like another router or switches?&lt;/P&gt;&lt;P&gt;I just assume that only packets with destination address 198.24.210.230(outside interface ip) can reach the outside interface from the edge router.&lt;/P&gt;&lt;P&gt;Is it wrong assumption?&amp;nbsp; If it is correct, then is there any way to route all packets with destination address 198.24.210.224/29 to the outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for helping.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/edge-router-connection-for-outside-interface-of-asa-5520/m-p/2209115#M350663</guid>
      <dc:creator>johnlee43</dc:creator>
      <dc:date>2019-03-12T01:37:46Z</dc:date>
    </item>
    <item>
      <title>Edge Router connection for Outside Interface of ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/edge-router-connection-for-outside-interface-of-asa-5520/m-p/2209116#M350664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If what you are saying is that you have a ISP router facing your ASA "outside" interface and that ISP Router interface that is facing your ASA holds the network 198.24.210.224/29 then there should be no problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is will route that whole network in their ISP Core and advertise it so traffic destined to any of those IP addresses from that netwokr 198.24.210.224/29 will reach the ISP Router/ASA wether you are using the single IP address in question or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess we were already discussing this same thing on another topic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you still having problems with reaching other IP addresses from the subnet? I would ask the ISP to confirm the configuration on their side and confirm that they can see the ARP for the public IP address that is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 15:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/edge-router-connection-for-outside-interface-of-asa-5520/m-p/2209116#M350664</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-02T15:55:36Z</dc:date>
    </item>
    <item>
      <title>Edge Router connection for Outside Interface of ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/edge-router-connection-for-outside-interface-of-asa-5520/m-p/2209117#M350665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To confirm your ASA configurations we would really have to see the configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 15:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/edge-router-connection-for-outside-interface-of-asa-5520/m-p/2209117#M350665</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-02T15:58:28Z</dc:date>
    </item>
    <item>
      <title>Edge Router connection for Outside Interface of ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/edge-router-connection-for-outside-interface-of-asa-5520/m-p/2209118#M350666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, lets consider the packet flow here. ISP gets a packet for an IP in range provided to you say198.24.210.230 (outside interface ip), it will send arp broadcast on segment b/w ISP router and ASA (considering it is the first packet and ISP has no arp entries for this subnet). Since IP is assigned on outside of ASA, ASA will respond to arp broadcast and ISP will be able to pass the frame to ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if packet comes for another IP in ranage which is not assigned anywhere (not on ASA outside or any other device in segment), no one will respond for arp broadcast and hence packet would be dropped as layer 2 lookup will fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, if you have NAT configured on ASA and you use these IP's in range as mapped IP's on outside, ASA will do proxy arp for those IP's and in that way all traffic would be routed to ASA outside. Normally, you would use static NAT for inbound traffic to your internal machines/servers or dynamic PAT to allow internet access to internal users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Sourav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 18:25:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/edge-router-connection-for-outside-interface-of-asa-5520/m-p/2209118#M350666</guid>
      <dc:creator>sokakkar</dc:creator>
      <dc:date>2013-05-02T18:25:35Z</dc:date>
    </item>
  </channel>
</rss>

