cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2095
Views
0
Helpful
7
Replies

MPLS router with firewall

yeow_km
Level 1
Level 1

Can i setup my network such that i placed a Cisco ASA firewall between my mpls router and cisco switch ?

---------------------                     --------------------                         -----------------                 ------------------

| MPLS Router |    -------------  | ASA Firewall |     ---------------  |   Switch     |   ------------ |    VLANs    |

---------------------                     ---------------------                        -----------------               ------------------

7 Replies 7

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Yeow,

this is possible, depending on support of MDIX or not you may need a cross-over cable between ASA and MPLS router.

Hope to help

Giuseppe

the ASA I m referring to is 5510. What mode do i configure for the ASA, routed or transparent mode is recommended ?

the mpls router is connecting to other remote office in the WAN.

Hello,

ASA cannot participate in MPLS label exchange. In routed mode, that will

result in breaking your MPLS communication. So, transparent mode would be

better.

Hope this helps.

Regards,

NT

Can the ASA do NAT in the environment as mentioned ?

Since MPLS router is already in private IP segment and switch is on another different private IP segment.

Hello,

In transparent mode, ASA cannot do NAT (in the latest version it supports

NAT to it's own IP) and is not recommended.

Regards,

NT

Hi

As per your senario it look like en enterprise network. So you won't requrie MPLS lable Propagation in your internet network.

If possible  can clear that weather you want to Propagate the MPLS Lable in you internet network or do you run MPLS in you routers & switchs  or do you have only an MPLS Link from your SP.

And if you won't require MPLS lable Propagation or you have not configured MPLS in intenal network  then you can configure ASA in routed mode & can use all feature that you requried.

Regards

Chetan Kumar

http://chetanress.blogspot.com

Hello Yeow,

if your site is a customer site of a L3 VPN, you can use the ASA in routed mode, this will allow you to interconnect the MPLS routers in the outside and the internal L3 switches on the "inside"

you probably just need to route between ASA interfaces, unless you have address overlapping with other sites or with the IP subnet used with the MPLS service provider.

Hope to help

Giuseppe