cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7633
Views
0
Helpful
12
Replies

ISR 4321 Ports & Configuration

tradepmrtech
Level 1
Level 1

Hello Everyone, 

I recently purchased a Cisco ISR 4321 router. My network layout requires me to put a firewall behind this router and have this firewall reachable via public IP address. My ISP has provided 2 ethernet hand-off with /29 network. I have only 3 usable IP address and I'm trying to put this router and firewall on the same IP range. I know that this router comes with only 2 native ethernet ports and I will need to purchase a NIM module for an additional port for firewall connection. I'm using the 2 native ports in BDI configuraion for the ISP hand-off. My question is that can I configure router and firewall this way? and which NIM module for the router will allow me to have this configuration? Let  me know if you have any other questions and any help will be greatly appreciated. Thanks. 

1 Accepted Solution

Accepted Solutions

Philip D'Ath
VIP Alumni
VIP Alumni

I like using the 4 (NIM-ES2-4) or 8 (NIM-ES2-8) port switch NIMs.

I don't completely understand your configuration.  Basically you want a public stub between your provider and your router, and then for your provider to route an additional block to your router.

If using a switch NIM you then create a VLAN and put one of the public IP addresses from the second block on that VLAN.  The firewall or other devices can then use IP addresses remaining from that second block.

View solution in original post

12 Replies 12

Philip D'Ath
VIP Alumni
VIP Alumni

I like using the 4 (NIM-ES2-4) or 8 (NIM-ES2-8) port switch NIMs.

I don't completely understand your configuration.  Basically you want a public stub between your provider and your router, and then for your provider to route an additional block to your router.

If using a switch NIM you then create a VLAN and put one of the public IP addresses from the second block on that VLAN.  The firewall or other devices can then use IP addresses remaining from that second block.

Thanks for your quick response. As for the IP address assignment, I'm trying to assign an IP address to router and firewall that's the same IP range. 

For example, if an ISP gives me the usable range of 72.22.222.222-224 with 255.255.255.248 subnet, can I assign 72.22.222.224 to the router and 72.22.222.225 to the firewall? 

ISR 4321 ==>  ASA 5520 ==> Switch

From your response, it seems like I would have to ask my ISP to give me another routed subnet for firewall use. 

Does the ISP provide you with a single Ethernet connection? If so, why not plug it directly into the ASA?

I'm trying to create a Routed-Based VPN with my Azure subscription and for that I need router for the configuration. I can connect the ISP hand off to the firewall directly but the firewall only supports Policy-Based VPN configuration. 

You could use the switch port NIM.  Plug the ISP and the Firewall into the same VLAN, and then they would all be in the same subnet.

I would personally get a second /29 for your configuration.

Hello,

You can also ask your ISP to give you a private range for connection between your router and ISP and then use the public range on your router or your ASA. This probably gives you more public IP addresses since you do not waste IPs for the ISP link.

Masoud

I don't think they can because they need to terminate an Azure VPN onto the router as well.  They need public IP address space.

What's the use for NIM-1GE-CU-SFP module? How is this different than the modules that you suggested above. I believe the native ports on the router are Layer 3 and NIM-ES2-4 might appear in the router as layer 2 ports. Just needed little more clarification of the module so I pick the correct one for my application. Thanks.

NIM-1GE-CU-SFP is a "full" routed layer 3 port.  The modules I suggested are layer 2 switch ports.

You can assign an IP address directly to NIM-1GE-CU-SFP, using it for L2TP, etc.

The modules I suggested allow you to assign the layer 2 ports to a VLAN and then put an IP address on it.  On the whole, they can't be used for advanced functions like L2TP.

Basically, I ended up using all ports on this NIM module. No native ports of the routers were used for this configuration. Since all NIM ports are switchports, I ended up creating a VLAN and making all switchports part of that VLAN. With this configuration, I was able to use the single /29 network from my ISP and configure both edge router and firewall on the same network. Thanks for all the feedback provided on this post. 

Hello, I have reviewed the entire router and can not find the compact flash. All that I found is a socket to place a flash like this:

 

4321 flash.jpg

Review Cisco Networking for a $25 gift card