cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

154
Views
5
Helpful
1
Replies
jjevans
Beginner

Two Cisco ASA in series

I have two Cisco ASA firewalls and would like to run these in series for a specific reason, but I would not like to get into the details. My question is how to make it work properly for inbound traffic to reach the 192.168.10.X network and outbound traffic to reach ISP from the 192.168.10.X network.

 

ASA Firewall One - Outside = 75.X.X.X (ISP) / Inside = 192.168.100.1

ASA Firewall Two – Outside 192.168.100.2 / Inside = 192.168.10.1

 

My assumption is a default route on the outside interface on Firewall One and a static route on Firewall one inside interface that points to Firewall Two outside interface.

 

ASA-One(config)# route outside 0.0.0.0 0.0.0.0 75.X.X.X.X

 

ASA-One(config)# route inside 192.168.10.0 255.255.255.0 192.168.100.2

 

And a default route on Firewall Two outside interface pointing to Firewall one inside interface.

 

ASA-Two(config)# route outside 0.0.0.0 0.0.0.0 192.168.100.1

 

Any insight is appreciated.

1 REPLY 1
balaji.bandi
VIP Master

that should work in routing point of view.

 

If the ASA 2 not doing NAT, then you need to add 192.168.10.X  in NAT  config on ASA 1

 

BB

***** Rate All Helpful Responses *****

How to Ask The Community for Help