05-30-2011 07:19 AM - edited 03-11-2019 01:40 PM
Hi all,
I have introduced a Cisco ASA to my Network so can someone explain me what is best operation mode for the security appliance?
the pros 'nd cons.
INTERNAL---->PROXY----->ASA5510------>Router----->INTERNET
Best Regards
Alcides
Solved! Go to Solution.
05-30-2011 10:45 AM
Hi Alcides,
The transparent does not support the following features:
NAT /PAT
Starting with ASA/PIX 8.0(2), NAT/PAT is supported in the transparent firewall.Dynamic routing protocols (such as RIP, EIGRP, OSPF)
DHCP relay
Quality of Service (QOS)
Multicast
VPN termination for through traffic
05-30-2011 07:26 AM
Hi Alcides,
No one could be a better judge of it than you yourself, if you need further in depth info about transparent mode, kindly go through the doc:
Also clearly go through the unsupported features of Transparent mode, this might be important for your requirement.
Hope this helps.
Thanks,
Varun
05-30-2011 09:36 AM
Hi Varun, thanks for your response. But the link you provided is forbidden for me. But in your opinion what's is the best operation mode thinking in security pespective?
like a frontend-backend firewall topology
Best Regards,
Alcides
05-30-2011 10:45 AM
Hi Alcides,
The transparent does not support the following features:
NAT /PAT
Starting with ASA/PIX 8.0(2), NAT/PAT is supported in the transparent firewall.Dynamic routing protocols (such as RIP, EIGRP, OSPF)
DHCP relay
Quality of Service (QOS)
Multicast
VPN termination for through traffic
05-30-2011 03:24 PM
HI Varun,
Many thanks your attention was very helpfully. so as you can see I'm new to ASA products. one last question what about the double Nat? many people just ask me about this( doing Nat in ASA and after in router) is there any problem doing that?
Best Regards,
Alcides
05-31-2011 07:24 AM
Hi Alcides,
If you are using the firewall in routed mode, y wud you do double nat, just do natting once on the ASA itself and routing on the router but if you are using the firewall in transparent mode then you would need to do natting on the router only.
Hope this helps.
Thanks,
Varun
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide