How to configure router in front of firewall

We are putting a Cisco 2611 in front of ASA 5510 to accept a DS3 circuit.  After circuit activation, 2611 can get out to Internet, but both internal user and ASA cannot access Internet.
The design is as following
Internal user <-> ASA e0/1
ASA e0/0 <-> 2611 gi0/0
2611 s1/0 <-> Internet. 
Internal user - ASA - 2611 - Internet
I'm not sure if I require additional NAT on 2611.  Can someone please provide help on troubleshooting this?
ASA has following config:
int e0/0
desc to 2611
nameif ISP
security-level 0
ip address 10.10.10.2 255.255.255.252
int e0/1
desc to internal
nameif internal
security-level 50
ip address 192.168.1.0 255.255.255.0
global (ISP) 1 interface
nat (internal) 1 192.168.1.0 255.255.255.0
route ISP 0.0.0.0 0.0.0.0 10.10.10.1
2611 has following config:
int gi0/0
desc to ASA
ip address 10.10.10.1 255.255.255.252
int s1/0
desc to Internet
ip address x.x.x.x x.x.x.x
Thank you,

Thank you John,
The ISP only provided a /30 block, and we won't be able to do the second option you suggested.  I configured nat on 2611 as following:
int gi 0/0
desc to ASA
ip address 10.10.10.1 255.255.255.252
ip nat inside
int s1/0
desc to Internet
ip address 2.2.2.2 255.255.255.252
ip nat outside
ip nat inside source static 10.10.10.1 2.2.2.1 //2.2.2.1 being ISP
ip route 0.0.0.0 0.0.0.0 2.2.2.1
ip route 192.168.1.0 255.255.255.0 10.10.10.2
ASA
int e0/0
desc to 2611
nameif ISP
security-level 0
ip address 10.10.10.2 255.255.255.252
int e0/1
desc to internal
nameif internal
security-level 50
ip address 192.168.1.0 255.255.255.0
global (ISP) 1 interface
nat (internal) 1 192.168.1.0 255.255.255.0
route ISP 0.0.0.0 0.0.0.0 10.10.10.1
Would this work?
Thank you,
Woo

Similar Messages

  • How to configure router to use ip pool on the aaa server for vpn clients

    how to configure router to use ip pool on the aaa server for vpn clients . i want to use vpn clients to connect to the router. authenticate using the aaa server username databse and also use the ip pool cretaed on the aaa server. i am not able to find the command on the router pointing to use the pool created on the aaa server. can u some one help me with this command.
    sebastan

    Hello Sebastan,
    what do you use as AAA server (e.g. ACS with TACACS+ or RADIUS) ?
    Regards,
    GNT

  • How to configure router in bridge mode

    Hi
    I have 2 cisco 2621 series routers to be configured in bridge mode.
    i'll be connecting this 2 routers using serial connection 128 lease line.
    the problem is im not sure how to configure this 2 routers in bridge mode.
    as far as i know, i need to issue the command no ip routing.
    is there anything else i need to do?
    can anyone guide me on how to configure
    the router in bridge mode? is there any support page for this is cisco website?
    thanks
    Jega

    Please check the link to the configuration guide below. It describes how to configure transparent bridging.
    http://www.cisco.com/en/US/products/sw/iosswrel/ps1831/products_configuration_guide_chapter09186a00800ca65a.html
    Regards,
    Leo

  • How to configure routing on site to site VPN(RV215W)

    Hi all
    I have set up a VPN between a RV215W and SRP521 (site to site)
    The VPN is up and connection is established on both side.
    However I cannot connect from one network to another (No ping, no connection)
    When I checked teh configuration, I noticed that route table on RV215W does not show any ipsec interface nor the route to the remote network
    Any hint how to configure this route over the VPN? Should I do it manually or is it a paramater to be made automaticaly?
    On the SRP215 the routing is as follow
    Destination LAN IP
    Subnet Mask
    Gateway
    Interface
    192.168.100.0
    255.255.255.0
    VLAN100
    192.168.15.0
    255.255.255.0
    VLAN1
    192.168.25.0
    255.255.255.0
    141.48.36.1
    ipsec0
    41.0.0.0
    255.0.0.0
    WAN1
    41.0.0.0
    255.0.0.0
    ipsec0
    0.0.0.0
    0.0.0.0
    141.48.36.1
    WAN1
    On the  SRP only local and WAN are displayed

    Hi,
    Don't worry about your English - it is good. I am not a native English speaker, either.
    You are correct - Cisco's IS-IS has no internal support for optional metrics. The only metric value that is going to be used in best path selection is the default metric. Regarding considerations about metrics in IS-IS, the only consideration I find important is that all new IS-IS deployments should use wide metrics. These can be activated using the metric-style wide in the router isis configuration. Wide metrics allow you to use a significantly wider metric range than the original IS-IS standard: 24 bits for interface metric, and 32 bits for total path metric. It is important to say that all L1 routers within an area, or all L2 routers in the domain must use the same metric type, either the classic (also called narrow) or the new wide metrics.
    Apart from that, there are no special considerations I am aware of. The choice of metric values for a particular interface is completely up to you. Of course you might want to configure lower metrics for faster interfaces (and vice versa), but what values you choose is up to you.
    Best regards,
    Peter

  • How to configure router with static IP

    Hi,
    I have requested a static IP from ISP provider.
    Now I would like to give static IP addresses to all my internal PC's using my Mac Extreme router.
    my ISP requires the Airport extreme to be configured in 'DHCP' (internet connection).
    If I use 'static' then the ISP router does not see my Extreme router.
    However my mac router does not allow me to use internet connection 'DHCP' when using router mode 'DHCP only'
    Can anybody give me a some tips?
    Thanks in advance

    You are talking about two completely different Static IP questions here.
    If your ISP has issued a Static IP address to you for the AirPort Extreme, this is the IP Address that you must use in order for your AirPort Extreme to connect to the Internet.
    Open AirPort Utility, click on the AirPort Extreme icon and then click Edit
    Then click on the Internet tab a the top of the screen.
    The setting for Connect Using must be set to Static, and you will need to enter in the IP address, DNS servers, etc information that your ISP has provided for you to be able to connect to the Internet. In the screenshot example below, you would enter the Static IP address that your ISP provided to you in the IPv4 box.
    For now, click the Network tab at the top of the screen and insure that the setting for Router Mode is set to DHCP and NAT.
    We first need to make sure that your AirPort Extreme can connect to the Internet using the Static IP address that you have been assigned.
    Then, we will tell you how to set up Static or Reserved IP addressed for each of your devices on your local network if this is what you want to do. Normally, this would not be needed, but it can be done if you wish.

  • How to configure route in sales order and delivery

    Hi friends,
    Can any one explain about Route determiantion steps. It has to take the route automatically in sales order and delivery also.
    i have configured
    shipping condition, transportation group, transportation zone, plant, shipping point determination, actual route by proposalroute.
    Apart from this what are the remaining steps, but it is not picking  in sales order and delivery.
    please any one send the steps for route determination. its very urgent for me.
    Thanks & regards
    Raju

    hi,
    Route is determined
    1.Country of Departure & Departure Zone taken from Shipping Point
    2.Country of Destination & receiving Zone from Ship to party
    3.Shipping condition from CMR
    4.Transportation Group from MMR
    5.Weight Group which is optional.
    Check the above.
    Route is determined in delivery.
    ASHA

  • I want to set up the Time Machine and I would love to use the Time  Capsule but since I already have a wireless router I need suggestions on  what other external disks Apple could recommend to use with the Time Machine and  how to configure that disk

    I want to set up the Time Machine and I would love to use the Time
    Capsule but since I already have a wireless router I need suggestions on
    what other
    external disks Apple could recommend to use with the Time Machine and
    how to configure that disk.
    A complication that I need to resolve is the fact that I am using Vmware
    Fusion to be able to use Windows on my Mac. Now it seems that Time
    Machine is not backing up my files
    on that virtual Windows without additional configuration and my question
    is whether you can advise me here or whether this is only a matter for
    the Fusion virtual machine.

    If you want to use Time Capsule you can.. you simply bridge it and plug it into the existing router.. wireless can be either turned off or used to reinforce the existing wireless.. eg use 5ghz in the TC which is much faster than your 2.4ghz.
    You can also use a NAS.. many brands available but the top brands are synology, qnap and netgear readynas  series. These will all do Time Machine backups although how well always depends on Apple sticking to a standard. There are cheaper ones.. I bought a single disk zyxel which was rebadged and sold through my local supermarket. It actually works very well for TM at least on Snow Leopard. Major changes were made in Lion and again ML so do not instantly think it will work on later versions. I haven't tried it yet with those versions.
    Any external drive can be plugged into the mac. Use the one with the fastest connection or cheapest price according to your budget. USB2 drives are cheap and plentiful. But no where near as fast as USB3 or FW800. So just pick whichever suits the ports on your Mac. Interesting Apple finally moved to USB3 on their latest computers.
    TM should exclude the VM partition file.. it is useless backing it up from Mac OS side.. and will slow TM as it needs to backup that partition everyday for no purpose.. TM cannot see the files inside it to backup just the changes.
    You need to backup windows from windows. Use MSbackup to external drive.. if you have pro or ultimate versions you can backup to network drive. But MSbackup is a dog.. at least until the latest version it cannot restore the partition without first loading windows. There are about a zillion backup software versions for windows.. look up reviews and buy one which works for you. I use a free one Macrium Reflect which does full disk backups and is easy to restore.. to do incremental backups though you have to pay for it.

  • How to configure one dsl connection and one public ip in cisco router and map to one interface for using exchange server

    how to configure one dsl connection and one public ip in cisco router and map to one interface for using exchange server

    Hi ,
     Have you got any additional public IP Address from your service provider , If yes on router you can have static route for those additional IP Address pointing to your ASA  outside interface . 
    Accordingly you can configure NAT 
    HTH
    Sandy . 

  • How to configure WRT350N as a router in a network wih a DSL modem/router

    Hi,
    I'll really appreciate if somebody please could give me some help.
    The problem is that I have a Dlink DSL-2640B modem/router AND a Linksys WRT350N router, what I want to do is how to configure them so they both are in the same network, and the WRT350N has access to internet and the computers connected to the DSL-2640B.
    Is that possible?....OR...the other option I was thinking was leave the DSL-2640B as a modem only, and have the WRT350 make all the routing wired and wireless.
    I'll really appreciate your comments.
    Regards.

    As per my knowledge it is better to use the wireless router to provide connection to wired & wireless computers. Leave the DSL2640B as a modem, connected to internet port on wireless router.

  • How Clean ip Route Table and configuration

    How Clean ip Route Table and configuration?
    Cisco have any best practice?

    Hey Juan,
    your question is not very clear but i believe you want to know how to clean ip route table and configuration. So:
    1. Cleaning IP routing table - clear ip route * - This will refersh the routing table.
    2. Cleaning configuration - It depends on the device however in most of Cisco devices you may clear the startup configurtion and its done :)
    HTH.
    regards,
    RS.

  • How configure router for one internet provider

    Just bought a router RV042G for commpany. Why does the router configuration requires two IP addresses for the two ISPs. What if we only have one ISP?
    How should i corectly configure router for one ISP (internet provider)
    Plese need ugent help!

    Hi, The peacedog.
    we have static ip adreess.
    I have a little problems with this rotuer. Could you plese help to configure it correctly.
    we have 100 mb internet conection with one static ip.
    rotuer RV042G
    switch: Cisco SF100-24 24-Port 10/100 Switch
    16 pc and 2 samsung network printers.
    Today i come to work and two pc had not internet conecction but had access to local network. other worked just fine. I tried to resset router and network stpped work at all. I tried factory default and backup restore config, it doesnot helped. So for luck i had wirelles router tp link and i replaced it and now all works just fine, but slow.
    Plese help. i am not IT specialist. How should i configure this router to work corectly?
    Before I noticed in system log many conection refuse notices to dropbox and to other services, how to solve that?
    P>S could you suggest how to make subnet and conect to it tp link wireless router for guests so that they dont see local network.

  • How to configure GlobeSurfer II umts modem router to act as just a modem

    Sorry if this has been asked before but after three days of searching I haven't been able to find an answer.
    I'd like to know how to configure a GlobeSurfer II umts modem router to act as just a modem allowing my TC to provide all the remaining wireless services.
    I know the combination can easily be made to work with the TC as in bridge mode but doing that loses features of the TC that I'd like retain.
    I've found a fairly comprehensive manual on line but it doesn't address my specific needs and I'm not techie enough to interpret the information that's provided into a work around.
    Thanks

    Hi Bob,
              many thanks for answering. GlobeSurfer suggested the following
    "the easiest is to use the Ethernet to connect the GlobeSurfer to your Capsule. Make sure that you have the 2 routers having difference IP address ranges and they don't overlap each other."
    That pretty much contradicted everthing I've read in discussions so I've asked for information on how to
    1. stop the GlobeSurfer from acting as DHCP and stop it providing IP addresses
    2. make the GlobeSurfer a client of the Time Capsule
    I was already using an e cable between the two but in the mean time I did the rest of what they sggested. The only warning I got on the TC was a "Double Nat" for which I clicked "ignore".
    As a result I have the two networks that I wanted, (one protected with private HDDs and printer attached and one guest), I can connect to the internet through both, I've been able to extend the main using an Extreme in bridge mode and there's no sign of a third network being produced by the GSII. I'm delighted and I'm stunned to say that it worked.
    It'll be interesting to hear what they come back with.
    Thanks again

  • How to configure users for internal mail routing only in exchange 2013

    Hi Guys!
    I have a scenario here that i have three (3) group of users, one group is able to have an inbound and outbound mail, meaning they can send and recieved emails from internal and external.The second group of users should have inbound mail(local mail) only
    (cannot send and recieved mails from internet), and the third (3) user is they can recieved an outbound mail but they are not allowed to send mail directly to the client,(Ex.
    [email protected],[email protected],[email protected]) instead they will use the
    [email protected] as the reply to the client. Please let me know how to configure group user 2 and 3.
    Thank you.
    regards,
    Paul

    Hi Paul,
    Great advice from Maganti, just elaborating steps:
    Prevent Group 2 send e-mail to internet by transport rule:
    1. Login EAC with administrator, Mail Flow---> Rule, click “Create a new rule, then give a name “Group2 - No Internet Mail”.
    2. Conditions: select "From a member of a distribution list" & select group "Group2"
    3. Select another condition "Sent to users inside or outside the organization" & Select Outside.
    4. Actions: select "send bounce message to sender with enhanced status code" & write your custom message like “You are not authorized to send mails to internet”.
    Prevent Group 3 directly send e-mail to internet, however it can send message as group:
    We also can create a transport rule which is same with Group2, then open Active Directory Users and Computers to add send as permission with another group (contain same users as group3).
    Best Regards,
    Allen Wang

  • How to configure users for internal mail routing only

    Hi Guys!
    I have a scenario here that i have three (3) group of users, one group is able to have an inbound and outbound mail, meaning they can send and recieved emails from internal and external.The second group of users should have inbound mail(local mail) only (cannot send and recieved mails from internet), and the third (3) user is they can recieved an outbound mail but they are not allowed to send mail directly to the client,(Ex. [email protected],[email protected],[email protected]) instead they will use the [email protected] as the reply to the client. Please let me know how to configure group user 2 and 3.
    Thank you.
    regards,
    LRMCP

    Hi LRMCP,
    Procedure is perfect which is given by Benoit, just elaborating steps.
    Prevent form Sending Mails:
    Create a transport rule on Hub Transport Server:
    Organization Configuration -> Hub Transport -> Transport Rules -> New Transport Rule -> Give Name “Group2 - No Internet Mail”
    Conditions: select "From a member of a distribution list" & select group "Group2"
    Select another condition "Sent to users inside or outside the organization" & Select Outside.
    Actions: select "send bounce message to sender with enhanced status code" & write your custom message like “You are not authorized to send mails to internet”
    Prevent from Receiving Mails:
    New User: You can select “require that senders are authenticated” while creating new users which will stop receiving mails from internet.
    User -> properties -> Mail Flow Settings -> Message Delivery Restrictions -> Properties -> set Sender Authentication.
    For Existing Users:
    You have already a group named "Group2" so set sender authentication for all members with this single command.
    Get-DistributionGroup "Group2" | Set-Mailbox -RequireSenderAuthenticationEnabled $true
    Same procedure mentioned for group2 can be followed for Group3 to prevent from sending mails.
    Amit Tank || MVP - Exchange || MCITP - Exchange 2007 || http://ExchangeShare.WordPress.com

  • HT1695 I use a Wifi router and I have to connect using a ppoe connection. Does iOS support that and how to configure it on aniPAD?

    Does anyone know how to configure a PPOE connection?

    Take a look at this thread.
    http://forums.macrumors.com/showthread.php?t=914983
    I think the answer is no. Not directly using ios.   

Maybe you are looking for