<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5510 IP Addresses question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167758#M351506</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to use the new IP address range on the "outside" edge of the firewall as NAT IP addresses or do you want to use the new IP address range directly on the new "dmz" so that the servers are directly configured with a public IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would not suggest subinterfaces. There really is no need for them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you share you ASA software level as this has an effect on the required configurations to make this work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has the ISP stated how they added the IP address range? Is it configured as a "secondary" IP address range on their upstream router/gateway? Or have they routed the said network towards your ASAs "outside" IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you let me know the above information and we can look what needs to be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have a section on this subject in my document I recently created (mostly regarding 8.3+ NAT format though)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-31116"&gt;https://supportforums.cisco.com/docs/DOC-31116&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Apr 2013 11:01:01 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-04-18T11:01:01Z</dc:date>
    <item>
      <title>ASA5510 IP Addresses question</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167757#M351504</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may seem like a basic question to th eexperienced engineers but I'm having an issue understanding how it works since I'm not that much knowledgable in this.&lt;BR /&gt;My question is regarding IP addresseing withint an ASA 5510 configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've been allocatied a range of IP addresses to use form our ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;62.7.80.192 /28 (Not reall Addresses)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;we've recently ran out of the allocated ones and been given a new range to add to the existing environment:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;217.33.240.192 /27&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Looks simillar to below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(DMZ)&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;ASA (Outside Interface 62.7.80.194) ----&amp;gt; (Gateway 62.7.80.193)&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;(Internal Network)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The routing is showing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 62.7.80.193, OUTSIDE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is how will be I be able to incorporate the new Address range so that new servers within the DMZ can access the outside world?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there an otion to have subintefraces on the outside interface one for the 62 network and one for the 217 network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you would any additional detail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:30:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167757#M351504</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2019-03-12T01:30:56Z</dc:date>
    </item>
    <item>
      <title>ASA5510 IP Addresses question</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167758#M351506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to use the new IP address range on the "outside" edge of the firewall as NAT IP addresses or do you want to use the new IP address range directly on the new "dmz" so that the servers are directly configured with a public IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would not suggest subinterfaces. There really is no need for them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you share you ASA software level as this has an effect on the required configurations to make this work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has the ISP stated how they added the IP address range? Is it configured as a "secondary" IP address range on their upstream router/gateway? Or have they routed the said network towards your ASAs "outside" IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you let me know the above information and we can look what needs to be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have a section on this subject in my document I recently created (mostly regarding 8.3+ NAT format though)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-31116"&gt;https://supportforums.cisco.com/docs/DOC-31116&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 11:01:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167758#M351506</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-18T11:01:01Z</dc:date>
    </item>
    <item>
      <title>ASA5510 IP Addresses question</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167759#M351508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your reply. Will answer your question soon once I get the details. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks again and apologies about late reply from me .. was on a course, then assigned to a project that just finished.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;KR&lt;BR /&gt;H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 12:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167759#M351508</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2013-05-23T12:00:37Z</dc:date>
    </item>
    <item>
      <title>ASA5510 IP Addresses question</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167760#M351510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My suggestion would be to simply create a second DMZ, say DMZ2, and just assign IP Adresses from the new range to the servers in that dmz. Of course, a new interface will be needed on the ASA for DMZ2. If you don't have an available interface, then you could convert the existing DMZ interface into a trunk to a DMZ switch, for example. On that switch you would have 2 VLANs, one for the old DMZ, one for the new DMZ. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Routing-wise, you don't need to do anything assuming the ISP routed the new range to your ASA. If you have some sort of perimeter router between your ASA and the ISP router, then you would need add a static route there for the new range to your ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 16:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167760#M351510</guid>
      <dc:creator>stefan.radovanovici</dc:creator>
      <dc:date>2013-05-23T16:15:00Z</dc:date>
    </item>
    <item>
      <title>ASA5510 IP Addresses question</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167761#M351512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the attached diagram, each one of the servers that sits on the existing DMZs has got a localized IP address within the range y.y.126.0, they also have a public IP address of x.x.89.206, and x.x.89.205.&lt;BR /&gt;We ran out of the x.x.89.0 range and we've been given a new range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on your reply, all that I need to do is when there is a new project, is to creat a new DMZ with a localized y.y.126.0 address, and a public address with one of the new ip addresses from within the new range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Routing on firewall should take care of things since it's got a default route, and all I need then is to ammend the policies depending on requirements for access in/out of the dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will also need to make sure that our ISP routed the new range to our lan as per your comment.&lt;/P&gt;&lt;P&gt;Please let me know if I understood your comment correctly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;H&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/1/2/141216-SP_ASA_Design.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 10:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167761#M351512</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2013-06-03T10:54:41Z</dc:date>
    </item>
    <item>
      <title>ASA5510 IP Addresses question</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167762#M351516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Haidar, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all we need to clear something out. When you say "&lt;SPAN style="font-size: 10pt;"&gt;&lt;EM&gt;each one of the servers that sits on the existing DMZs has got a localized IP address within the range y.y.126.0, they also have a public IP address of x.x.89.206, and x.x.89.205.&lt;/EM&gt;", what exactly do you mean ? Do the servers only have a local ip from y.y.126.0 configured on on their NICs and x.x.89.205/206 are just NAT IPs configured on the ASA ? Or the servers actually have two IP Addresses configured on their NICs ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;If x.x.89.206 are NAT'ed IP Addresses (which the ASA translates to y.y.126.0) then you don't need another interface. You just need to use IP Addresses from the new range assigned by the ISP to NAT to IPs from x.x.126.0, which you will assign to&amp;nbsp; the new servers. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 11:56:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167762#M351516</guid>
      <dc:creator>stefan.radovanovici</dc:creator>
      <dc:date>2013-06-03T11:56:33Z</dc:date>
    </item>
    <item>
      <title>ASA5510 IP Addresses question</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167763#M351517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies about confusing the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are single servers that sit on the DMZ with a NAT rule on the firewall for their external Public IP address to be translated to the local address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 08:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167763#M351517</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2013-06-04T08:44:00Z</dc:date>
    </item>
    <item>
      <title>ASA5510 IP Addresses question</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167764#M351521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hello Haidar, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;No problem. Then you don't need to do much, a new interface is not needed in this case. Just place your new servers in the existing DMZ VLAN, assign them the local IPs out of y.y.126.0 (assuming you have free IPs there) and then just create the needed NAT translations on the ASA using external IPs out of the new range assigned to you by the ISP. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As long as the range is correctly routed to your ASA, it should work without any problems. The ASA itself does not need to have an IP out of the new range configured on any of its interfaces, it'll just use proxy arp to attract traffic for the new range. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Stefan&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 08:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ip-addresses-question/m-p/2167764#M351521</guid>
      <dc:creator>stefan.radovanovici</dc:creator>
      <dc:date>2013-06-04T08:50:11Z</dc:date>
    </item>
  </channel>
</rss>

