12-09-2021 01:15 AM
Hello Guy,
How to configure the cisco Asa so that all data traffic from the clients is routed through the existing cisco Asa firewall ?
A fritzbox is currently the default gateway. In addition, an existing mail server should also be hung behind the cisco ASA
where we can find a cisco guide or configuration to do that ?
Thank you very much
Cheers
12-09-2021 01:40 AM
You need to set ASA firewall relevant inside interface ip address accordingly at the clients. If you want to set default in ASA, then please follow this link.
Solved: default gateway ASA 5505 - Cisco Community
12-09-2021 02:32 AM
Morning Ashok
Thank you very much for your reply and solution.
That means, we only have to configure a default route 0 0 0 0/0 with our Gateway IP Address on outside interface, right?
Then all clients traffic will goes through the cisco ASA, right?
In addition, an existing mail server should also be hung behind the cisco ASA, I hope that won´t cause any issue
Thank you again and regards
12-09-2021 03:05 AM
12-09-2021 06:29 AM
Hello Ashok,
Thank you again for your support regarding this topic. we really appreciate it
Only to make sure, it is clear to me what I have to do. please feel free to correct me if I am wrong.
On the client (Laptop) site, we have to configure the Gateway IP address
and on the Cisco ASA via (CLI or ASDM) we have to configure the default route 0.0.0.0/0 with the same IP Gateway like on the client site (Laptop) on outside interface
that is what I have to do, right ?
Thank you once again
12-09-2021 11:14 PM
I am talking in general...
ASA Inside interface IP address let's say - 10.1.1.1/24 & then let's take the client IP address as 10.1.1.2 with default gateway set to "10.1.1.1".
And then, you also configure a default route on ASA pointing to a Router for eg with IP address 192.168.1.1 like below. The Router is default gateway for ASA to reach external networks & below default route is pointing through ASA outside interface.
"route outside 0.0.0.0 0.0.0.0 192.168.1.1"
Pls follow the below link for details.
12-10-2021 02:02 AM
Morning Ashok.
Thank you again for all the information you provide and for all your help.
I would like to send you the setup scenario we are talking about
How can I send you the setup scenario please to have a look?
Best Regards
12-12-2021 02:27 AM
12-12-2021 04:32 AM
Hello Ashok,
Thank you for your reply.
The attached file is the current and new setup scenario design.
I am asking myself right now if it will be better to remove both ISP provider router from the new design and connect the ASA Eth1 and Eth2 interface to the ISP 1 and 2 network and the ASA Eth3 to the intranet and every LAN user will use the IP gateway of the LAN network
So I don´t know where I will connect the mail server if we decide to remove both ISP routers from the new design because the Mail server is actually connected to ISP1 router.
what could be the benefit and inconvenient by removing or keeping both ISP provider in the new design?
I am not sure but I think we can move them.
your opinion / idea will be very great appreciated
Thank you very much
Best Regards
12-13-2021 02:37 AM
I feel you can go with your new design. And, Mail servers are generally put in Inside zone or DMZ zone depends upon your business requirements.
Please find the following link for the details.
12-13-2021 03:23 AM
Hello Ashok,
Thank you for your email.
So it make sense to go ahead with the new design without both ISP router , right?
or we should keep them in the new design
I think the ASA can do all both ISP routers are able to perform
Cheers
12-13-2021 03:42 AM
12-13-2021 08:10 AM
Hello Ashok,
Thank you very much for all your support regarding that problem. I will do it like that and let you know how good it is working
we really appreciated all information you provided to me
Cheers
12-09-2021 02:43 AM
I take this as below setup you proposing :
ISP -fritzbox -ASA --your network.
Make sure you disable SMTP inspection on ASA - and need to do relevant network Routing and NAT
12-09-2021 07:11 AM
Hello Balaji,
That is exactly the setup
good point, disable SMTP inspection on ASA for ever or only before we start the configuration?
which network routing and NAT configuration we can need in this case please ?
Thank you very much
Best Regards
Bertrand Abega
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide