03-04-2021 06:28 AM
Hi Community,
We need our server and device in vlan 1 go through MS Switch not the Firewall
Thank you
03-04-2021 06:37 AM
Then point the device to Switch as a gateway, add a static default route on switch towards ASA.
From ASA add static route entries for 192.168.1.0/24 towards switch IP 192.168.1.3
Switch static route 192.168.1.1 (ASA)
device gateway 192.168.1.3
03-04-2021 06:51 AM
Hello
Can you post a topology diagram please.
03-04-2021 07:36 AM
Hi Paul,
to not change the default getway in all the server and device that take static rout ,just we need to replace ip of ASA(current getway192.168.1.1) with (MS-250 switch192.168.1.3)
Thank you
03-04-2021 08:12 AM
thank you for the diagram - @Giuseppe Larosa suggests another option - other than my default reply.
03-04-2021 07:33 AM
Hello @tech44048 ,
a clean design would require an additional VLAN like VLAN 50 for ASA to switch communication
VLAN 50 192.168.50.1/24 on ASA side and 192.168.50.2 on MS250 side
ASA ---- VLAN 50 ---- switch MS250 ---- VLAN 1-40
on ASA you will have
route 192.168.1.0 255.255.255.0 192.168.50.2 inside
route 192.168.20.0 255.255.255.0 192.168.50.2 inside
route 192.168.30.0 255.255.255.0 192.168.50.2 inside
route 192.168.40.0 255.255.255.0 192.168.50.2 inside
on switch
ip route 0.0.0.0 0.0.0.0 192.168.50.1
>> In ASA we create rules for exchange server (open port: pop/imap/SMTP), if we change the gateway, the rules still work?
Yes with the proposed setup the server will have def gateway 192.168.1.1 on switch and switch will route to ASA on new VLAN 50
Hope to help
Giuseppe
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide