12-27-2018 11:32 PM - edited 02-21-2020 08:36 AM
Hi,
I really need someones help with this I am a bit stumped.
I am configuring the one design latest .but i am struck in this design.let you tell me to how to configuring the ASA firewall ,router and switches to will get the internet and filtering of traffic in laptops.what configuration will make.
i am attached the my design diagram below
please give your outputs those ASA firewall ,Cisco router and Cisco switches.
12-28-2018 12:01 AM
Hi,
My recommendation is to go with Router >> ASA >> Switch >> PC's.
Router will take care the routing features with ISP and ASA, ASA should take care the NAT and filtering of traffic towards your users.
Thanks,
Abheesh
PS: Please don't forget to rate and select as validated answer if this answered your question
12-28-2018 12:47 AM
12-28-2018 01:09 AM
You should tell us a little bit about your design goals. For me, the router between the ASA and the switches seem completely useless. If you want different subnets internally, do L3-switching on one of the switches. If you want filtering between the VLANs, then remove the router and configure the VLANs on the firewall. Or you can combine both approaches with some internal VLANs terminated on the L3-switch and some (like guest vlans) terminated on the firewall. And with a small setup like this, it's unlikely that you have to put a router between the firewall and the ISP.
12-28-2018 01:36 AM - edited 12-28-2018 01:40 AM
Thanks Iwen,
Natting is also we used
My Actual intention is filter traffic in ASA firewall .This my new configuration actually i want to know what is the best configuration i am implemented here,we different Vlans here.
We Have 2 L3 3750 Cisco Switch ,5 2960 Cisco switches ,one 2911 router and one 5520 ASA firewall(9.x) we have also Wireless 2504 Cisco WLC
Kindly tell me how to configure
12-28-2018 02:02 AM
In that case I really would dump the router as it is not needed here. And I would replace the ASA as this device is EOL and operating an EOL security device puts your network at risk (and even worse, depending on the rights in your country, you could be legally responsible for that if something happens).
My setup would be the following:
ISP - ASA - L3 3750 - 5* 2960 and WLC
12-28-2018 02:37 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: