06-16-2022 12:18 PM
06-16-2022 01:57 PM - edited 06-16-2022 11:35 PM
Hello
looking at your topology i would say the default route should point to the asa as most probably that is the gateway for external network traffic.
By the way the default does not have to be a connected or next hop ip/interface sometimes it can be a recursive static default which isn’t one of the above - it can be a next hop ip address related to another route existing in the route table so for traffic to reach its destination via a recursive route the rtr will lookup the recursive nexthop ip address and find another route that will then be used to forward the destination traffic.
06-16-2022 12:23 PM
is this switch acting as Layer 2 ?
If the firewall is HA mode you should have VIP IP, so you can point to that IP address.
example :
https://www.networkstraining.com/cisco-asa-active-standby-configuration/
06-16-2022 12:33 PM
The switch has SVI ip address
06-16-2022 12:34 PM - edited 06-16-2022 12:41 PM
if the north is active ASA then Yes you can.
06-16-2022 12:36 PM
Hello,
the short answer is: no. The default gateway (or default route) needs to point to a next hop address. So 10.61.10.1 will not work.
06-16-2022 01:57 PM - edited 06-16-2022 11:35 PM
Hello
looking at your topology i would say the default route should point to the asa as most probably that is the gateway for external network traffic.
By the way the default does not have to be a connected or next hop ip/interface sometimes it can be a recursive static default which isn’t one of the above - it can be a next hop ip address related to another route existing in the route table so for traffic to reach its destination via a recursive route the rtr will lookup the recursive nexthop ip address and find another route that will then be used to forward the destination traffic.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide