08-23-2011 07:32 AM - edited 03-04-2019 01:22 PM
Hello everyone,
I would like to push route for admin services (Vlan20) to bypass the firewall via an other connection (CSI to CSE).
so my first choice was to create a route-map in (CSI) but I don't know how to do it.
on my Firewall ASA, I don't have any Context License, that is why I would like to do it like this.
I have included some part of my initial configuration CSI and CSE and diagram.
Does anyone know if this would work? Or Does anyone have a better way of doing this?
Any help would be appreciated!
Thanks
Paul
CSI configuration (Switch L3 3750)
{
interface GigabitEthernet1/0/1
description To ASA
no switchport
ip address 10.22.250.18 255.255.255.252
!
interface GigabitEthernet1/0/2
description To CSE
no switchport
ip address 10.22.250.22 255.255.255.252
!
interface Vlan10
description Employees
ip address 10.22.23.254 255.255.252.0
interface Vlan20
description Admin
ip address 10.22.239.254 255.255.252.0
router eigrp 1
passive-interface default
no passive-interfaceGigabitEthernet1/0/1
network 10.0.0.0
no auto-summary
}
CSE configuration (Router 2811)
{
interface FastEthernet0/0
description To ASA
ip address 10.22.250.14 255.255.255.252
duplex auto
speed auto
interface FastEthernet0/1
description To CSI
ip address 10.22.250.21 255.255.255.252
duplex auto
speed auto
router eigrp 1
passive-interface default
no passive-interface FastEthernet0/0
redistribute static
network 10.0.0.0
no auto-summary
ip route 0.0.0.0 0.0.0.0 Dialer0 (+ip public) }
08-23-2011 10:44 AM
Paul
It should work as is because the CSI device will see a directly connected route to the CSE device and so should route over the dedicated link. And vice-versa for the return traffic. Have you set it up and it is not working ?
As for whether it is a good thing to do, in all honestly no it is a terrible thing to do because if the outside switch is compromised there is now a direct path into your LAN which bypasses the firewall.
Why can you not just send the admin traffic through the firewall as well. This is a standard thing to do.
Jon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide