cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
623
Views
0
Helpful
1
Replies

Firewall & OSPF

wasiimcisco
Level 1
Level 1

My firewall A will be connecte with Router A and use the OSPF.

Only firwall interface that is connected with router will use the OSPF and interface that is connected with switch will have the static routes.

I will redistrubte the static rotues into the OSPF domain via my firewall.

All internet will be use by the Firewall C. Now the problem is that I am not able to find out which interface should i put in ospf domain, If i will put outside interface in ospf domain, i have to make static and acl for all entries that are coming from OSPF domain. bcz Enterprise network will use Internet via Firewall C as mention in the diagram.

what do u think about no-nat-control and nonat solution.

Any solution regarding this will be highly helpful.

1 Reply 1

htarra
Level 4
Level 4

In many instances, you need to enable routing on the Firewall to connect to devices on networks that are not directly connected. This is accomplished by manually configuring static routes or by using Open Shortest Path First (OSPF) to dynamically learn routes.redistribution of firewall routes was separated from static routes.

http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/bafwcfg.html

Review Cisco Networking for a $25 gift card