Hi experts, I would like any suggestions on this topology. We are is the middle of replacing our old ASA5520 with the new FirePower. Our current firewall terminate our IPsec tunnels and the GRE is terminated on the first inside router's loopback on the secure side of the firewall. Our consultant is proposing to have a router on the side DMZ with the sole function to terminate the GRE so that the firewall can inspect the data. I'm no expert in firewall but I'm thinking that there has to be a better way. Can we terminate the IPsec and the GRE in the firewall so the data can be inspected? Or is a router facing the internet in front of the firewall in the only solution? Thank you!
... View more
Is anyone ran in to this problem. I have those 9 port switch cards installed in 2921 router and in several different occasions my multicast source would go inactive sometime intermittently and other time permanently. Rebooting the Router always fix the problem. I have also noticed in couple occasions a port would dead and the end device connected would not respond to anything. If I connect on a local port on the same switch it is working I can communicate with the dead port. It seems like the router won't talk to the switch port and again if I reload the router the problem goes away. I have 60 of those routers with that 9 port switch card and I have multiple strange problem and all of the seem related to some problem with the router communicating with its switch card intermittently. I run ISO 15.2 in my Cisco 2921.
... View more