09-18-2018 07:45 AM - edited 02-21-2020 08:15 AM
Hello,
We are migrating a juniper netscreen to a Cisco ASA. The firewall is running BGP with the upstream routers. The netscreen has a loopback interface created with subnets that are used for nating. The loop back is created to inject the nat networks into BGP.
My question is how do you achieve this on a Cisco since it does not support loopback interfaces?
1 - use null routes? We found one article that suggested creating NULL routes for the natblocks and that will allow the subnets to be injected into BGP. But we tried that in the lab and having weird results. Not sure if its our config or if using the NULL routes is a bad idea.
2 - Static route on the router? Even though we are running bgp between router and fw.. can I add a static route as well from router to the fw?
3 - any other thoughts?
Thanks.
09-18-2018 08:23 AM
09-18-2018 08:54 AM
Everything inbound doesn't seem to be working... We can see on the router's routing table the route been learned via the firewall so we know bgp is advertising the route correctly, however, we can't pass traffic.
Unfortunately, our MX window was over and we had to rollback before troubleshooting further... We are thinking about static routes as a second workaround... Proxy ARP issue should be fixed by having the "arp permit-nonconnected" command, don't you think?
Thanks,
Juan Lombana
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide