cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
516
Views
0
Helpful
5
Replies

Can i point default gateway to the north of Firewall? Recommend?

aannuupp1
Level 1
Level 1
1 Accepted Solution

Accepted Solutions

Hello
looking at your topology i would say the default route should point to the asa as most probably that is the gateway for external network traffic.

 

By the way the default does not have to be a connected or next hop ip/interface sometimes it can be a recursive static default which isn’t one of the above - it can be a next hop ip address related to another route existing in the route table  so for traffic to reach its destination via a recursive route the rtr will lookup the recursive nexthop ip address and find another route that will then be used to forward the destination traffic.

 


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

View solution in original post

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

is this switch acting as Layer 2 ?

 

If the firewall is HA mode you should have VIP IP, so you can point to that IP address.

 

example :

 

https://www.networkstraining.com/cisco-asa-active-standby-configuration/

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

The switch has SVI ip address

if the north is active ASA then Yes you can.

Hello,

 

the short answer is: no. The default gateway (or default route) needs to point to a next hop address. So 10.61.10.1 will not work.

Hello
looking at your topology i would say the default route should point to the asa as most probably that is the gateway for external network traffic.

 

By the way the default does not have to be a connected or next hop ip/interface sometimes it can be a recursive static default which isn’t one of the above - it can be a next hop ip address related to another route existing in the route table  so for traffic to reach its destination via a recursive route the rtr will lookup the recursive nexthop ip address and find another route that will then be used to forward the destination traffic.

 


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul
Review Cisco Networking for a $25 gift card