cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1251
Views
0
Helpful
6
Replies

Discontiguous IP blocks to Same ASA5510

n_schloemer
Level 1
Level 1

I currently have an ASA5510 that has it initial IP block being provided by the DC, recently the company has had a need for a new IP block which has been given to us by the same DC but is also discontiguous from our original block.  I have ponder best possibilities to configure the outside interface to accept the new block but wanted to get some other opinions.  Any ideas would be greatly appreciated.

Thanks!

2 Accepted Solutions

Accepted Solutions

varrao
Level 10
Level 10

Hi Nick,

You can use them until and unless those public ip's point towards the ASA outside interface by your service provider, it shoudl be fine, you can configure them on the ASA.

Thanks,

Varun

Thanks,
Varun Rao

View solution in original post

Yes that will work SP route pointing to your interface will bring traffic upto your outside interface of Firewall and based on your  requirement you can allow traffic by using ACL. Nothing much is really required.

View solution in original post

6 Replies 6

varrao
Level 10
Level 10

Hi Nick,

You can use them until and unless those public ip's point towards the ASA outside interface by your service provider, it shoudl be fine, you can configure them on the ASA.

Thanks,

Varun

Thanks,
Varun Rao

So essenstially nothing fancy really needs to be done so the ASA recognizes the new block.  As long as the SP routes that block to the external inteface of my ASA and I create rules to allow the IP block through it will work?

Yes that will work SP route pointing to your interface will bring traffic upto your outside interface of Firewall and based on your  requirement you can allow traffic by using ACL. Nothing much is really required.

alright great, guess i was over thinking it.  I will give this a shot with some acl rules and get back shortly.

thanks.

Sure no problem, let me know if you face any issues.

Varun

Thanks,
Varun Rao

Yes Nicholas, thats correct, you just need to do the configuration that you have done for the previous /block on the ASA.

Hope that helps.

Thanks,

Varun

Thanks,
Varun Rao
Review Cisco Networking products for a $25 gift card