Cisco Firewall Overlapping Internal Network Issue
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2016 03:25 PM - edited 03-12-2019 01:30 AM
I am trying to protect an internal network from another internal network on the same subnet with a cisco 5505 firewall. I don't know if it is possible with the conifguration my boss would like to implement but I have attached a jpeg photo of the layout.
- Labels:
-
NGFW Firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2016 03:34 PM
Do I need a router to get traffic on the same subnet to anoter network on the same subnet through the firewall?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2016 06:38 PM
Hi,
Yeah you need another device in between, it's not possible to configure 2 firewall interfaces on the same subnet unless you have multi-context mode which is not supported on the 5505.
Even if you get that router in between, you'll have to do full network source address translation on the ASA and the router in order to protect the overlapping network.
I know you mentioned the addressing can't be changed but it seems the best route you can take is to break that class C subnet into two /25 nets.
HTH
Pablo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2016 09:17 AM
Yep. I am going to change the subnet on one network and assign others to the servers.
