asa interface assignments

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2014 10:32 AM - edited 03-05-2019 12:04 AM
I have two public ip ranges from the isp that I’m assigning to my asa 5512. One range is a /29 and the other range is a /26. I’ve assigned the /29 as nameif outside and the /26 as nameif inside. Are there any anamolies with this design. I’m wondering if it would be better to assign the /29 as outside and use a private range for inside and then translate that to the /26. It is currently working way it is but I’m wondering about whether it is worth changing it. Thanks
- Labels:
-
Other Routing

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-03-2014 09:55 AM
Are you using the /26 public address space on your internal network?
Generally, the inside is going to be your private IP space and you use the /26 for public facing services on a DMZ and for outbound NAT purposes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-04-2014 05:59 AM
I would agree that the usual approach is to use the /26 for address translation without assigning it to an interface or to use it in a DMZ. But if it is working ok currently assigned to the inside interface then it might not be worth changing it.
HTH
Rick
Rick
