adsl as backup for internet connection thru PIX
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-16-2005 09:54 PM - edited 02-21-2020 12:08 AM
my client has mpls connection to the internet connected on the OUTSIDE interface of the firewall. And they decided to have an ADSL to act as a backup for their internet connectivity.
Ive read that we can only have a single default route on the PIX. What could be the best solution to this issue.
Thanks a lot.
- Labels:
-
Other Network Security Topics
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2005 12:09 AM
You can ask mpls provider to run OSPF between PIX and PE.
Provider will advertise only defalt route to the PIX.
On the pix you must have got default static route to ADSL with administrative distance greater than 110.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2005 03:59 AM
thanks. but how will my firewall know that the link on the mpls is down taking into account that the mpls switch port connected to the outside of the pix is always up?
thanks again.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2005 04:04 AM
The pix version 7 software supports up to 3 equal cost default routes. However, you best option would be a router that as your current connection and a ADL connection into it and use the "backup interface" command to control the fail over.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2005 09:16 PM
My MPLS connection is thru a 3550 switch and not a router.
Is the backup interface command to be executed on the switch or the firewall?
Thanks a lot.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-18-2005 05:34 AM
The backup interface command is used on a router, surely you are installing a router to use with the ADSL line?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-18-2005 09:16 PM
but the way i understand backup interface is executed on the main connection. ADSL in our case is a secondary (backup) internet connection.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-19-2005 12:13 AM
yes, that is correct.
What I was trying get at, was that if you have a router for your ADSL you could speak to your ISP and arrange for the MPLS to be terminated on a router so that you could use adsl as a backup. In fact, you really shold get your ISP involved to ensure that your IP addreses etc are routed correctly when using the backup.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-20-2005 09:25 PM
But in my case, the MPLS connectivity is a 3550 and the adsl is a separate router and i dont have access to the MPLS switch. Does this mean am handicuff this time?
thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-22-2005 09:38 PM
I couldnt find any mid range router that is supporting MPLS. Could you help me on this?
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-22-2005 10:31 PM
2691 and higher
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-23-2005 12:10 AM
If you use a dynamic routing protocol you can setup the network like this:
LAN --- Cisco --- 3550 --- MPLS
2621
\---ADSL
and use the dialer watch command, this allows you to watch routes and use the backup if the routes disappear. Take a look at:
Warning: this is my understanding, I haven't tried it in the real world......
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-23-2005 12:55 PM
nice suggestion..but is adsl considred as DDR?..this is one of the prerequisite in usng dialer watch that was shown on the above link.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2005 10:09 PM
Hello Matt ,
Just want to know that is it possible to assign Dynamic IP on PIX outside Interface connected to the DSL Router??
Network Setup:--
----Internet----DSL Router----PIX(506E)----LAN
Note: - We don’t have any static IP .
Thanks
vijay
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2005 10:09 PM
Hello Matt ,
Just want to know that is it possible to assign Dynamic IP on PIX outside Interface connected to the DSL Router??
Network Setup:--
DSL Router----PIX(506E)----LAN
Note: - We don’t have any static IP .
Thanks
vijay
