Drop 'N Go subnet within pre-existing network - Help with routing please

Hello All,
I would consider myself entry level at best when it comes to the Cisco ASA 5505, and I appreciate any help or direction that anyone would be able to provide regarding this issue I am having. I am sure there is something out there for this but I have not yet been able to figure this out with what I have found.
So we currently have our infrastructure setup like this: modem(69.14.72.6/255.255.255.248)->ASA(192.168.1.1)->Switch->Hosts and Servers(192.168.0.X\24).
What I am trying to do is drop in a small router somewhere within this network with its own subnet and be able to communicate back and forth to it from the 192.168.0.X network, so it will look something like this: modem->ASA->Switch->Hosts and Servers(192.168.0.X\24) && Hosts and Servers(192.168.1.X\24).
I would like to allow this traffic flow hopefully while only having 2 interfaces configured on the ASA (Outside 0/0, and Inside 0/1-0/5) and without modifying the configuration on the Switch. A few key phrases that come to mind from my search thus far are "Hair Pinning" and "same-security-traffic permit intra-interface". Also I am aware of port-forwarding, and as I understand it this would not be practical as I would have to configure a rule for every device connected to the 192.168.1.X\24 network.
I hope someone will be able to help me with this issue, I have been at this for 3 weeks now.
Thanks again everyone!
EDIT: Here are is a diagram to help explain what I am trying to do. The area shown in red is what I am trying to add to the rest of which I already have.

Hi,
I've made this in packet tracer (I had to use a router instead of ASA - but same principle applies.)
This is the classic "Router on a stick" topology.
Note: You'll need to create a trunk between the switch and R1 now that there are 2 VLANs.
## I've used 192.168.0.2 as the gateway address for the 192.168.0.x network, but you could in fact set up the router R1 with 192.168.0.1 as the subinterface, get everything configured, and then install the router and change the current internal address of the ASA (192.168.0.1) as per my example, at the very last minute. ##
The ASA will need a route added for traffic back to the 192.168.0.x and 192.168.1.x networks.
The 192.168.1.x network -- gateway will be 192.168.1.1
The 192.168.0.x network -- gateway will be 192.168.0.2
*There's no need for any of the subjects you mentioned:
 "Hair Pinning" and "same-security-traffic permit intra-interface" or port-forwarding.
HTH
Ian

Similar Messages

  • Using WRT45G wireless router with a pre-existing network?

    I am an NYU student, so I am already connected to a pre-existing network. However, I would like to have wireless internet in my room, so I bought the WRT45G router. Is it possible to do this? I don't have an actual, physical modem. There is just an internet jack in my room.

    Yes. Simply hook up the Internet port of the WRT to the internet jack. Then plug your computer to a LAN port. Configure your WRT going to http://192.168.1.1/ (default password is "admin" unless you have changed that).
    1. Set the router to "Automatic Configuration - DHCP".
    2. Save Settings.
    That should do it. You should be able to check the Status tab and see that the router got an IP address from your campus network.
    For the security of your network and your computer I highly recommend to do the following things as well. Don't forget to save the settings for each page where you make changes.
    - change the router password. You can do that on the Administration tab.
    - change the SSID to something else than "linksys" on the Wireless tab.
    - turn off the SSID broadcast after you have connected your computer for the first time wireless. (Wireless tab)
    - turn on wireless security (on the wireless security subtab). Choose WPA2 Personal if possible (i.e. your computer allows it). Else WPA Personal. Choose TKIP or TKIP+AES depending on the setting before. Enter a pre-shared key (a stronger password or passphrase). You must enter the identical key in your computer when you connect the first time.
    Without wireless security anyone can use your router and most likely is able to connect to your computer as well. Therefore: use it!

  • Hi I got an email from itunes saying that my pre order was ready and when I click on the link from my ipad it takes me to the itunes store app and then it doesn't do anything help with this please.

    Hi I got an email from itunes saying that my pre order was ready and when I click on the link from my ipad it takes me to the itunes store app and then it doesn't do anything help with this please .
    <Link Edited By Host>

    Thanks for your advice, I went to the apple shop today for a face to face meeting with a tech and he checked everything and could not figure out why I was having this problem so we decided to give up on that account and create a whole new one for me using a different email address.
    Now I can download apps on both my iPhone and ipad2.
    If anyone is reading this in Brisbane Australia go to the Chermside apple shop and ask for Wade. He was fantastic!
    Jan

  • Will Airport Express find network printers on existing network on Linksys Router

    If Airport express is connected to an existing network hosted on Linksys router, will it discover the network printers already on the network?
    I hope to use Airport Express to extend my network to iPhones to print and to play music.

    If Airport express is connected to an existing network hosted on Linksys router, will it discover the network printers already on the network?
    If an AirPort Express is configured to "join" an existing wireless network, it will perform as a wireless client and not as a router. It cannot discover other network printers and share them out. Instead if you connect a printer to the Express' USB port it can share out this printer.
    Also, the Express cannot extend a wireless network provided by a non-Apple router ... at least not if the connection between routers will be wireless.

  • WRT160n set up trouble in existing network -help please

    It's a small business office. Cable modem comes into a Netgear smart switch, which distributes LAN to desktops and a older Wireless router.
    So I hook up the router as directed, setup won't complete...  error no router found.
    Of course 192.168.1.1 is the netgear switch, so that's not available.
    Grr.
    I tried seemingly everything. Plugged it into the cable modem Lan ports, plugged it into the Netgear Lan posrt, put it in serial with a computer into the Netgear. Blah.
    There's no usb connector to port into. 
    Ideas?
    Thanks in advance! 

    Open an Internet Explorer browser page on your wired computer(desktop).In the address bar type 192.168.1.1 and press Enter...Leave Username blank & in Password use admin in lower case...Under the Setup tab,the router ip address is 192.168.1.1...So change it to 192.168.1.2.Power cycle the entire network and it should work.

  • Can I keep and use my pre-existing file structure with Aperture?

    I currently use and love Picasa.  I moved over from a PC and have all my photos in folders named by date and subject.  That keeps everything in order... and I can search easily.
    I would love to use the editing features of aperture which exceed Picasa's.  If I use Aperture, I know I can leave my pictures in the folders they are in... but does Aperture have a left sided pane that allows me to see and browse my folders as easily as Picasa?   Or is there an equivalent function?
    Any advice, particularly from someone who has used both, would be appreciated.
    Thank you.

    You can import your photos in their current location.  However, you won't be able to easily "browse" them from within Aperture.  Aperture is essentially a database program and so it's not for browsing file location on disk.  Photos can be anywhere, and Aperture can easily move them around.
    I'll also note: Photos that are imported into Aperture should _not_ be moved around on disk via Finder after the fact.  That is, unless manually updating their locations within Aperture is your idea of a sport or a hobby ;-)
    Aperture is a different kind of application than Picasa.  I'd suggest watching the video tutorials at www.apple.com/aperture to get some idea of how it works.

  • Pairing pre-existing cable cards with TiVo

    I have two M CC's for separate TiVo HD units.  I am now having the CCI issue in VHO1 and thus need to pair my CC's to my respective devices.  Since I don't have an activation code is there a way to do this online using the Home Agent as long as I have the other information from the cards?

    The pairing is something you can not do on your own, but I will be glad to assist. I have sent you a private message to get more info from you.
    Thanks,
    Anthony_VZ
    **If someones post has helped you, please acknowledge their assistance by clicking the red thumbs up button to give them Kudos. If you are the original poster and any response gave you your answer, please mark the post that had the answer as the solution**
    Notice: Content posted by Verizon employees is meant to be informational and does not supersede or change the Verizon Forums User Guidelines or Terms or Service, or your Customer Agreement Terms and Conditions or plan

  • Need help with routing a network in VMware.

    I have one network with the IP of 192.168.2.10. A router is setup with two networks. The first network has an IP of 192.168.2.3 and the second network has an IP of 192.168.3.2. Then there is one final network whose IP is 192.168.3.10. My goal is to set
    up route table entries and have all the networks be able to ping each other. The route table entries I am referring to is the
    route -p add command. If someone could help me understand what entries I should input so all the networks can ping each other, that would be great. Thanks. If you need a picture of the network, I have a diagram. 

    Hi Brandon,
    A diagram or picture will help us to understand your case.
      For dump file or other logs which do not contain the sensitive information, you can still use OneDrive to share them so that other community members can also provide help in analysis.
      If you concern personal information or company related information in logs, we recommend to send log files to our forum email account: [email protected]
    Regards,
    D. Wu
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Creating a LAN within an existing LAN using a spare router?

    My other option is to use my phone as personal hotspot and use it's internet. Would that work?

    Hello,I would like to set up a personal lab environment within an existing LAN that has router(s), switches, server, etc(basically the whole deal). That LAN operates on one IP subnet 192.168.100.0/24(I'm not sure, but I think DHCP for that subnet is running on the router which is the default gateway to the Internet.)
    I have a spare router here. May I plug that router into the switch under my desk that connects to the 192.168.100.0/24 LAN and configure my spare router like so that it has its own LAN behind it such as 192.168.99.0/24 or 10.1.10.0/whatever, have that router think that the 192.168.100.0/24 subnet is actually the Internet access, and have a DHCP server running on my spare router that specifically servers my subnet only, not the outside 192.168.100.0/24 network. Then I will set up my own domain controller(s), file servers,...
    This topic first appeared in the Spiceworks Community

  • How many Airport devices do I need to extend an existing network?

    Hello all,
    I hope one of you might be able to help me with a problem.
    I recently just moved to a different apartment, and my router (from my local internet provider) does not reach to all the rooms in the apartment.
    Since I also wanted to stream wireless music in my home office I read that the Airport express would be a great solution to both extend the existing network and stream wireless from my Apple products.
    I went to buy the Airport express, and asked the guy in the local authorized reseller of Apple products, if I could use this without connecting it via cables to my router (hence using it via wifi only). And he said yes, which I believed. However, after trying to set it up, and failed. I started searching for questions about my issue.
    So:
    Do I need two airport devices if I want to extend my existing network, when the router is in the living room, and the speakers that I want to stream from are located in my home office in the other end of the apartment? The area that I want to extend the existing network to is the bed room, next to the office.
    So I thought that I could set the Airport express up in my office and connect it to the mini-jack from the speakers, and voila it would just do as I wanted to. But since I'm not a technical expert, I might have misunderstood, and I really do not want long ethernet cables running all over the place.
    Is the only solution then to buy two devices? (Oh and for your information, I am not able to move the router to the office since there is no outlet for the internet, the only place it can be set up is in the living room).
    Hope someone can help enlighten me on this issue. Thank you :-)

    You need two AirPorts if you want to wirelessly "extend" the network, which will provide more wireless coverage....since both AirPorts will be broadcasting a wireless network.
    You only need one AirPort Express if all that you want to do is use it for AirPlay to pick up the wireless signal and "join" your existing wireless network. In order to do this, the Express must be able to receive a good wireless signal from your router.
    To test if you have a good signal, take a laptop or mobile device to the area where you want to install the AirPort Express and check to make sure that you can get a good wireless connection at that location. If you can, then the AirPort Express should work well at the same point.

  • Mac Pro won't recognize airport card or existing network

    I have a 2007 Macbook in the house with an old Belkin MIMO router. the wireless netwrok works fine. In fact, my son waltzes in and says "hey what's the wireless password?" and logs on INSTANTLY on his Macbook Pro.  Now we have a (desktop) Mac Pro with a new Airport Extreme card, and the Mac Pro cannot find the network - it's only 5 feet away. The name of the network does not appear where the network names should populate. We've typed it, and the WPA password in 100 times, and nothing, justs keeps asking the same question. Filling in PPPOE info doesn't work either.
    NOTE: We do NOT have the airport extreme base at this house. We simply want the Mac Pro to FIND the existing network (Belkin wireless router and good old Airport on the 2007 Macbook so the Mac Pro can get on the internet wirelessly.
    Anyone have any ideas? Is the bios just not recognizing the new Airport Extreme card? How should it be configured?
    Thank you!

    There are four tiny black wires inside, three of which must be correctly connected to the AirPort card before you have any hope of connection over wireless.
    Stay away from PPPoE unless you have been told by your ISP that there is no other possible way to log on to the internet.
    Turn OFF IPv6 if possible.
    If the card is functioning, you get an Airport/WiFi pane in System Preferences > Network. You will also see it in System Profiler.

  • RIP V2, network command with classless address yield to classful

    As we know that RIP V2 is Classless while V1 is Classful.
    Obviously there are other differences. Cisco has mentioned them in CCNA3 V3.1 Article 1.2.3
    RIP V2 supports prefix routing with VLSM so different subnets within the same network can have different subnet masks.
    A(config)#router rip
    A(config-router)#ver 2
    A(config-router)#network
    A(config-router)#network 172.16.2.0
    A(config-router)#^Z
    A#sh run
    *Apr 7 05:36:29.422: %SYS-5-CONFIG_I: Configured from console by console
    A#sh run | b router rip
    router rip
    version 2
    redistribute eigrp 12 metric 2
    network 11.0.0.0
    network 172.16.0.0
    network 192.1.14.0
    Why has the value been changed from 172.16.2.0 to 172.16.0.0 ?
    What is the point of using RIP V2 if it yields to same result as RIP V1 ?

    Although ripv2 is classless, the configuration of which interfaces are attached to the rip process is classfull.
    In this case of yours, all interfaces configured in the range of 11.0.0.0/8, 172.16.0.0/16 or 192.1.14.0/24 will be attached to the rip process. If an interface exists with subnet 172.16.2.0/24 it will be advertised as such.
    Hope this helps,

  • Using airport time capsule to create an internet connected network from pre existing wifi network

    i bought an airport time capsule for college. I bought it to create a network for my dorm room so that I could take the pre existing wifi from the school and make my own mini network that I can hook my other stuff up to. Problem is that I don't have an ethernet hook up in my room so the network would have to be created from a wifi network rather that a ethernet hook up. Is this still possible? Alternate suggestions? I am afraid of either the college network blocking users from communication with other devices via the wifi, or the fact that my printer would be on a huge network for all to screw with.

    Is this still possible?
    NO, it won't work. Apple only works with apple.
    Alternate suggestions?
    I am sure your college has rules about not running your own wifi networks.. but anyway.. that is up to you.. the Apple TC cannot turn off 2.4ghz which would be handy.. so the only way to do this following the rules is ethernet. You can run a full network standalone on ethernet. And still use wireless for internet.
    If you want to use wireless standalone this is also possible but you need to connect a second wifi USB dongle your Mac so you can have two networks at once.. You can use an express to connect to the college wireless and bridge that to the TC by ethernet.. then use the TC to create your own network.. since you cannot turn off 2.4ghz I guess how long the College IT people take to track you down should be hours. If you could just use 5ghz it would probably be ok.

  • AE drops when connected to existing network, works great on its own

    When I have my AE connected to an existing wireless network, it keeps dropping out. But when I have it on it's own network, it NEVER drops out.
    Does the AE rely on the existing wireless router signal strength when it is connected to an existing network?
    thanks

    Any thoughts?

  • Re4000w drops when trying to make initial connection to existing network

    I am trying to set up a re4000w for a friend.
    I am attempting setup through the browser, connecting to 192.168.1.1. No issues seeing their existing network, I am able to connect and enter a p/w and the device will attempt to connect to the exisiting AP. However, after 10 seconds or so, the connection completely drops and the default extender SSID dissapears and does not reappear. The browser window goes white. 
    I have hard reset numerous times.  It was already runing 1.0 but I refreshed it. I have taken the device out of their home, and attempted to set up ay my own place and the same exact behavior takes place. 
    I know that the default gateway ay my place is 192.168.1.1, could this be creating some sort of comflict since the extender has the same default IP? I would think that once connected, the re4000w would grab a IP from the existing router and disable it own DHCP server. 
    Any ideas? Thanks

    If you configured the RE to extend an exiting wireless signal, once configured it will drop it's default signal and start broadcasting the SSID it was configure to extend.
    After the RE is configured the only thing you will notice on your wireless device is an increase signal for the extended SSID.
    Have you used a extender as a repeater before or have they all been hard wired to the router as an AP?
    Please remember to Kudo those that help you.
    Linksys
    Communities Technical Support

Maybe you are looking for