<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall &amp; OSPF in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-ospf/m-p/1000445#M940585</link>
    <description>&lt;P&gt;My firewall A will be connecte with Router A and use the OSPF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only firwall interface that is connected with router will use the OSPF and interface that is connected with switch will have the static routes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will redistrubte the static rotues into the OSPF domain via my firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All internet will be use by the Firewall C. Now the problem is that I am not able to find out which interface should i put in ospf domain, If i will put outside interface in ospf domain, i have to make static and acl for all entries that are coming from OSPF domain. bcz Enterprise network will use Internet via Firewall C as mention in the diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what do u think about no-nat-control and nonat solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any solution regarding this will be highly helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:20:39 GMT</pubDate>
    <dc:creator>wasiimcisco</dc:creator>
    <dc:date>2019-03-11T12:20:39Z</dc:date>
    <item>
      <title>Firewall &amp; OSPF</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ospf/m-p/1000445#M940585</link>
      <description>&lt;P&gt;My firewall A will be connecte with Router A and use the OSPF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only firwall interface that is connected with router will use the OSPF and interface that is connected with switch will have the static routes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will redistrubte the static rotues into the OSPF domain via my firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All internet will be use by the Firewall C. Now the problem is that I am not able to find out which interface should i put in ospf domain, If i will put outside interface in ospf domain, i have to make static and acl for all entries that are coming from OSPF domain. bcz Enterprise network will use Internet via Firewall C as mention in the diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what do u think about no-nat-control and nonat solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any solution regarding this will be highly helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ospf/m-p/1000445#M940585</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2019-03-11T12:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall &amp; OSPF</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ospf/m-p/1000446#M940586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In many instances, you need to enable routing on the Firewall to connect to devices on networks that are not directly connected. This is accomplished by manually configuring static routes or by using Open Shortest Path First (OSPF) to dynamically learn routes.redistribution of firewall routes was separated from static routes. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/bafwcfg.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/bafwcfg.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Mar 2008 16:22:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ospf/m-p/1000446#M940586</guid>
      <dc:creator>htarra</dc:creator>
      <dc:date>2008-03-27T16:22:27Z</dc:date>
    </item>
  </channel>
</rss>

