06-26-2012
01:29 PM
- last edited on
03-25-2019
03:36 PM
by
ciscomoderator
This is probably a little bit of a weird question but being fairly new to Cisco devices and having some specific 'building physical' limitations I thought I'd ask it anyways. Someone might even understand what I mean and might be able to help me achieve what I want/need.
The current setup is as follows: Virginmedia Superhub in modem mode connected to one Cisco C2950 on port fa 0/23. The 2950 is connected to a Cisco C3550 over fa 0/24 via normal Cat 5e.
Port fa 0/23 on the 3550 have a Astaro/Sophos UTM connected to it that acts as a Firewall/Wireless controller etc. The hitch, or maybe one of them, is that the 3550 and the UTM is on another floor from the 2950 and cannot be moved. The Virginmedia superhub can't be moved to the other floor either due to limitations in the cabling.
What I'd like to achieve is for the UTM to pick up the public IP from the Virginmedia cable modem whilst no other devices on the Lan should be able to connect to the cable modem. All inbound/outbound internet traffic should go through the UTM for security reasons. The UTM have a number of available nic's that can be set to dhcp, static etc.
I already have a number of VLANS on the router/switch and have half a suspicion that using another VLAN for this purpose might be the way forward but I'm not sure... It is almost like doing a 'interface forward' or something?
Any input is really appreciated. I know this is a bit fuzzy so please ask if you need any clarifications.
Thanks in advance, Mike
06-26-2012 06:25 PM
Hi Michael, an easy way for me to aproche it keeping in mind that you have different vlans would be to configure interVLAN routing, or a router in the stick configuration... I have added a link to a guide to get down with the configuration..
http://www.cisco.com/en/US/tech/tk389/tk815/technologies_configuration_example09186a00800949fd.shtml
also look at this document
let me know if it helps some...
Regards
Willy
06-27-2012 12:15 AM
Willy,
Many thanks for your reply. This looks like a very good start for me to go on with.
Hopefully by assigning the new VLAN to the port on the router (3550) where the UTM is connected it will be able to pick up the DHCP address from the cable modem connected to the switch (2950).
The next step would then be to make sure that all in/outbound internet traffic are routed via that public IP that's been assigned that way.
But that's the next step, let's see if I can get the VLAN communication to work first.
Once again - many thanks for pointing me in this direction.
Cheers, Mike
06-27-2012 06:19 AM
you probably have to subnet to your router and your switch will have to go with the modem dynamic ip from your cable modem.. but here is a document for the 3550..
Regards
Willy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide