07-14-2014 04:19 AM - edited 03-11-2019 09:27 PM
Hi,
We are assigned some IP’s from our ISP, Subnetmask /27. Actualy 217.x.187.194-198 and from 217.x.187.203-213 The IP’s between are given to someone else. This should be 30 available hosts. GW 217.x.187.193
I will use the range 217.x.187.194-198 for my internal networks.
Question. Will there be a problem not having entire full subnet or is this possible on the ASA 5505? Or should I ask for a complete range?
Also, is there any possibility to do static nat through the asa and allow all traffic from IP 217.x.187.196 to another router on the inside. This router belongs to another company who needs to regularly open and close ports through to their company. we do not want to give out access to ASA.
Br
Fredrik
07-14-2014 04:58 AM
Hi,
If we are strictly talking about having the 2 subnets on the WAN interface of the ASA then that is no problem at all. Though you have to consider the fact that ASA can not have 2 different subnet configured on a single interface (in your case a Vlan interface). But there is a way to implement that, the second subnet just is not configured under any interface. The subnet and/or its IP addresses are only present on the ASA in its NAT configurations.
There is 2 ways you can handle this with your ISP
To avoid any ARP related problems and other problems I would suggest that you ask the ISP to route the second subnet towards the ASA WAN IP address. Much more simple that way.
Now you mention that you want to do a Static NAT on the ASA for the internal router? This should be no problem and there should not be any problem allowing all traffic to the internal host when it has the Static NAT configured.
Since you have 2 public subnets you also have the option to configure the second public subnet directly on the internal interface of the ASA and the other company can use the public IP address directly on their Router. Naturally configuring this second subnet on the ASA might waste some public IP address (since you need one for the gateway etc.) but it completely depends on your setup.
Hope I made any sense :) Feel free to ask more if needed
- Jouni
07-14-2014 05:16 AM
Thanks for fast answer.
Actually it's the same subnet. 217.x.187.192/27 only the ISP gave us the first ip's (194-198) then maby 1 year later the other ones (203-213) other IP's in the range the ISP have given to somone else.
/Fredrik
07-14-2014 05:33 AM
Hi,
Guess I was reading a bit too fast and missunderstood the situation a bit. Sorry about that :)
So am I correct to assume that you would now have at your disposal the 217.x.187.192/29 range? (192 - 199). I assume you mean this as you specify the .193 used for GW and .194 - .198 being the usable IP addresses from that range.
I guess in that situation I would use the subnet 217.x.187.192/29 between the ISP and the ASA and would have the ISP route all the rest of the IP addresses free from the /27 subnet towards the ASA WAN IP address.
Naturally it would be ideal to have either a single subnet or several subnets so there is no need for anything special though in this case the complexity is on the ISP side. You should be able to utilize the /29 subnet and all the IP addresses that the ISP has routed towards your ASA.
- Jouni
07-14-2014 06:27 AM
Yes, You assume correct.
I will call the ISP right now and make sure this is doable.
single subnet would be best. But if this is doable then we do not need to change IP's. We have allot of connections to inside systems.
Thanks
/Fredrik
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide