I have replaced my old cisco 5510 Firewall with a new 5516 NGFW. My edge router 2911 has primary and secondary IP address on a LAN connecting interface. Before replacing the old firewall, primary and secondary IP gateway addresses were reachable from LAN users. After the replacement, primary gateway is reachable from lan side but secondary is not reachable. Please see the below packet flow diagram and running config of cisco ASA 5516-X
End Users -------> Switch 2960-X ------> Transparent Firewall 5516-X -------> 2911 Router ------> Internet
End users IP: 192.168.0.254/24 and Gateway 192.168.0.3
End users IP: 192.168.222.254/254 and Gateway 192.168.222.3
All ports in VLAN-2. Gig 1/0/24 is connecting inside interface of Firewall.
Interface VLAN-2 IP is 192.168.0.6/24 and Gateway 192.168.0.3.
Interface bvi 2 ip address is 192.168.0.9 255.255.255.0
Default route towards 192.168.0.3
BVI 2 is mapped on Gig 1/1. Gig 1/1 is an inside interface connecting with switch 2960-X. Security Level 100
BVI 2 is mapped on Gig 1/8. Gig 1/8 is an outside interface connecting with Router Gig 0/0. Security Level 0
inside interface policy is permit any any.
outside interface policy is source 192.168.0.3, 192.168.222.3 and destination any, service any, action permit.
ICMP is allowed on global inspection policy.
Gig 0/0 primary IP is 192.168.0.3/24 and secondary IP is 192.168.222.3
... View more
I have just replaced my old firewall 5510 with 5516-X. With old firewall, router's primary/secondary LAN IP was reachable from end user machines. But After replacing the old firewalls, primary LAN IP gateway is reachable from lan side but secondary gateway is not reachable. Config file of 5516-X is attached.
End users ------> Switch 2960-X -----> Transparent Firewall 5516-X ------> Router 2911 ------> Internet
All ports of the switch 2960 in vlan-2. Interface VLAN-2 IP on switch is 192.168.0.6 and GW is 192.168.0.3
Firewall 5516-X in Transparent Mode.
Firewall inside interface Gig 1/1 is connecting on switch port 1/0/24 in vlan-2. Inside Security level 100.
Firewall outside interface Gig 1/8 is connecting on router Gig 0/0 interface. Out side Security level 0.
Firewall inside interface policy (any any permit)
Firewall outside interface policy is Source (192.168.0.3 & 192.168.222.3), Destination any, service any and action permit.
Firewall Interface bvi 2 IP is 192.168.0.9/24. Bridge group 2 mapped on outside and inside interfaces of Firewall.
Firewall default route is 192.168.0.3.
Router Gig 0/0 primary IP ( 192.168.0.3)
Router Gig 0/0 Secondary IP (192.168.222.3)
End user with a IP:
192.168.0.254/24 GW 192.168.0.3
End User with a Secondary IP:
192.168.222.254/24 GW 192.168.222.3
With old firewall 5510, End users are able to reach secondary gateway IP (192.168.222.3). But after replacing new firewall 5516-X secondary LAN IP is not reachable. Please assist me in this regard.
... View more
Kindly share your experiences regarding how can I check the serial number of power supply of cisco 2960s via CLI ?
show inventory and show version do not show desired information.
... View more