How do you promote a static route over a directly connected?

Hi all,
I have a need for a static route to be used instead of a directly connected route. (Long story - involving firewalls and anti-spoofing.. but can go further if required)
I am using a Cisco 3750 switch. I notice directly connected routes have a metric of 0, and the highest metric I can give a static route is 1.
Therefore, how is it possible for me to make the switch use the static route and not the directly connected?
Any help would be appreciated!
Cheers,
Ben

Hi Rick,
Thanks for your patience.
Maybe I should start again.
Initially we had 16 VLANs within the 10.0/16 address space. We have some Cisco 3750's connected by dark fibre accross a couple of kms and then lower access switches all hanging of these by some means. The network is flat.
We have a checkpoint firewall hanging off one of the 3750s connected using a TRUNK port. The firewall has an IP address on all VLANs and is used to route traffic between VLANs based on its ruleset.
So if I have a user in VLAN 10 who wants to talk to VLAN 20, they travel to the firewall, if a rule permits the access, the firewall routes the packet on to VLAN 2 and the switches deliver at Layer 2.
The switches all have their default VLAN 1 disabled, and have an IP address on our management VLAN to allow us to manage the switches.
Its quite important that this IP is on a secured management VLAN as we don't want just anyone being able to snoop switch logins etc..
If we need to login to a switch, the firewall routes our traffic from whatever VLAN we are on to the Management VLAN.
One of our VLANs (the Desktop VLAN) is quite large (approx 1300 hosts) and suffers a great deal from too much arp broadcast traffic.
As we have a flat switched network across several kms, the cost of putting in routers to subnet this large VLAN is excessive.
However, the 3750's we have are perfectly capable of routing between VLANs, so we decide to create a load of new VLANs instead of subnetting our large VLAN. We don't want to use the firewall to route between these new VLANs as thats just giving the firewall more to do, and previously all these hosts were on a single subnet, so we have no need for any strict security - at most we can use ACLs on the switches if we even need that!
So far so good.
With 1300 hosts, we obviously can't make sudden topology changes. Therefore we need to be able to route between the Desktop VLAN and the new VLANs.
We therefore introduce the static routes between the firewall and the switches.
So the firewall says:
route 10.1.0.0/16 via Multilayer switch IP on 10.1.0.0/16
The multilayer switch says:
route 10.0.0.0/16 via Firewall IP on 10.1.0.0/16
This allows routing perfectly between the Desktop VLAN and the new VLANs.
However the moment we enable ip routing on the switches we break access between the desktop VLAN and the Management VLAN.
A packet leaves the desktop VLAN through the default gateway on the firewall. This is then routed to the Management VLAN. The return packet doesn't use the Management VLAN default gateway (firewall), it follows the static route on the switch and ends up at the firewall on 10.1.0.0/16. This is subsequently dropped as the firewall knows the packet hasn't come from the 10.1.0.0/16 network, it originally came from the desktop VLAN on 10.0.0.0/16.
It might seem we can define a route on the switch to say:
route 10.0.50.0/24 (management VLAN) via 10.0.50.254 (firewall). However, this would result in all packets from 10.1.0.0/16 being dropped by the firewall.
The other problem is that if we are on a new VLAN and want to talk to the management VLAN. The packet goes to its default gateway on the switch. The switch says - "I have an IP on the management VLAN, its directly connected" - therefore it ignores the static route, and passes the packet on its way. We have now bypassed the firewall, which is bad.
Incidentally the return packets get routed through the firewall and dropped, as the original packet didn't come through the firewall, there is no entry in the state table for its return.
I think if we turned off the management interface on the switch and managed it through the interface on 10.1.0.0/16, I assume everything would work. However, we don't want to do this for a whole load of other reasons I wont go into.
Im sure there must be a fairly simple solution - I just don't have enough experience!
Cheers,
Ben

Similar Messages

  • How do you find your static ip

    How do you find your static IP adress?
    I am attempting to run a Minecraft Server Portforwarding

    If you look in System Preferences (under the Apple menu) select the Network pane. Select the network interface you are using from the list on the left - probably AirPort or Ethernet. If you are using Ethernet the IP address will be displayed right there. If AirPort, click on the Advanced... button, then the TCP/IP tab.
    Note that if either of these says Configure IPv4: Using DHCP you do NOT have a static IP address. If you want one you'll have to find out if one is available from your network administrator, change the Configure IPv4 menu to Manually and enter all of the addressing information.
    Note that some Internet Service Providers do not allow running a server on their consumer networks due to the amount of traffic it generates. Check with them first.

  • How do you resolve the problem of ipad not staying connected to internet. other laptops remain connected but ipad just disconnects after about 5 seconds.

    how do you resolve the problem of ipad not staying connected to internet when other devices are connected. Ipad disconnects after about 5 seconds.

    Look at iOS Troubleshooting Wi-Fi networks and connections  http://support.apple.com/kb/TS1398
    Additional things to try.
    Turn Off your iPad. Then turn Off (disconnect power cord) the wireless router & then back On. Now boot your iPad. Hopefully it will see the WiFi.
    On your iPad go to Settings > General > Reset > Reset network settings and see if that enables you to connect.
    If none of the above suggestions work, look at this link.
    iPad Wi-Fi Problems: Comprehensive List of Fixes
    http://appletoolbox.com/2010/04/ipad-wi-fi-problems-comprehensive-list-of-fixes/
     Cheers, Tom

  • How do you share a form fillable pdf in adobe connect?

    How do you share a form fillable pdf in adobe connect? ItI used to do it like I would share any other document but now it says "could not process document for viewing." Anyone know what cahnged and how to fix it?

    I hope its not preview.

  • HT1420 How do you find list of actual devices that are connected to your itunes account?  I'd like to know before deauthorizing, exactly what devices it is showing as connected

    How do you find list of actual devices that are connected to your itunes account?  I'd like to know before deauthorizing, exactly what devices it is showing as connected

    Click here and ask. If the iTunes Store staff doesn't give it to you, no.
    (86004)

  • How do you print from an iPad to a printer connected to a Time Machine?

    how do you print from an iPad to a printer connected to a Time Machine?

    Use a 3rd party app such as Printopia.

  • Im wondering how would you do a scrolling page over a static background?

    I watched this and its great https://www.youtube.com/watch?v=qRC5-GKYa_Q but im wondering how would you do this over a static background?

    Hi Paul,
    This is done using Parallax Scrolling. Static back ground should not be a problem in achieving this. Please try it and let us know if you face any issue.
    Regards,
    Aish

  • How do you make the color bleed over the margins for a cover

    Hello,
    We currently do our covers in InDesign but want to move them into our FrameMaker book file. There is a block of color at the top of the cover that we want to go to the edge of the cover. How do you set it up so that the color bleeds about 1/8" past the edge of the paper so that the printer can properly cut the cover without any white on the edges?
    It's an 8-1/2 x 11 book, created with Frame 9 on a Windows XP Professional.
    Thanks,
    Tim

    How are you creating the PDF and which version (including point release) of FM are you using?
    To create bleeds, you were on the right track positioning the graphic off the page by a negative amount. However, you don't increase the size of the page in your FM layout, you output to a larger sheet size (i.e. pick this in your AdobePDF printer setup or the Page Size in your SaveAsPDF options ). Unfortunately, you won't be able to preview this in FM. Look to your PDF to see what's going on. Note: SaveAsPDF *always* applies a crop value equal the FM defined page-size layout; in Acrobat for PDFs created via the SaveAsPDF route, you have to turn off the crop to see the entire media box with the bleed values.
    If you're using FM10, make sure that you're patched to the latest 10.0.2p419 version. This is the only version that makes reasonable CMYK PDFs for print production, all prior FM10 & FM9 versions are quite buggy (for CMYK) and are not recommended for the CMYK route (you have to use the Convert CMYK to RGB option in this case and fix up in Acrobat or with third-party tools like the Enfocus PitStopPro plug-in for Acrobat).

  • How do you scroll down on Voice Over

    How do you scroll down on VoiceOver?

    hi,
    when you get to the settings option , do not tap the screen instead swiftly touch and drag the screen wiht three fingers , and you can actully go toaccesibility .
    i was crazy wiht this thing for 2 days but somehow could get an answer.
    pl try this

  • How do you reset an E2500 router?

    Sorry if this is the wrong place to post this but I'm on my iPod and browsing is not very easy. Thanks

    Welcome to the Cisco Home Community.
    Flip the E2500 over and you'll find the reset button.
    Additionally, you may also refer to this link on how to reset your router to defaults.
    The Search Function is your friend.... and Google too.
    How to Secure your Network
    How to Upgrade Routers Firmware
    Setting-Up a Router with DSL Internet Service
    Setting-Up a Router with Cable Internet Service
    How to Hard Reset or 30/30/30 your Router

  • How do you make a static reference to a method?  I've included code.

    I'm sorry but this is a cross post. This should be here but it is also in the 100% pure Java forum. It won't happen again.
    Now...
    Why doesn't this work? How do I use the method add(int a, int b)?
    ERROR - "Can't make static reference to method int add(int, int) in testClass"
    interface testInterface{   
        static String sString = "TESTING";   
        public int add(int a, int b);
    class testClass implements testInterface{
        public int add(int a, int b){
            return a+b;      
        public static void main(String argv[]){
            int sum = add(3,4);    // here's the error
            System.out.println("test");
            System.out.println( sum );   
    }Again, I apologize for the cross post.

    hi,
    this seems to be pretty easy, isn't it?
    Oh c'mon! You try to invoke a non-static method from within a static method. Solution: Create a specific instance of class testClass:
    testClass test=new testClass();
    test.add(3,4);best regards, Michael

  • How do you get your contacts moved over to your iphone4?

    i just got my new iphone 4 and i had a droid 2 before i cant seem to get my contacts moved over. so is there a easy way to get them on there?

    Are the contacts stored on the SIM card on your droid or synced to your Google account?
    If they are on the SIM card, you're kinda out of luck as the Droid and iPhone use two different types of SIM cards.
    If they are synced with your Google account, simply set up the Google account on the iPhone and sync the contacts.
    The User's Guide for the iPhone would also be a good resource to browse.

  • How do you download a static file using a FileReference and URLRequest and show the progress?

    All,
       I'm trying to download static content (PDFs) off of my server using tutorials from adobe's site and some online as well and i'm having no luck showing an updated progress bar.  I attached the meat of my code below.  If a user clicks a hyperlink, it calls the downloadPDF method passing in a constant url defined.
      When debugging, i can see that the event.bytesLoaded is incrementing on each call to the progress method, however the bytesTotal is only set to the intitial number of bytes transferred on the first pass through the method.  (Ex:  First time the method is called, bytesLoaded and bytesTotal will be 4,000... which i dont understand... the bytesTotal should be the total size of the file being downloaded.. definitely not the case...  the next time the method is called, bytesLoaded will increases to some number while bytesTotal will remain at 4,000).  This happens during the entire file transfer.
    Am i missing something? Are the examples incorrect?  Also to note, i'm using sdk 3.2 (Not sure if that makes a difference.)
    Thanks for any response or insight.
    Damian
    <mx:Script>
            <![CDATA[
                import com.ctc.fema.resources.Buttons;
                import flash.net.FileReference;
                private var fileRef:FileReference;
                private var urlReq:URLRequest;
                 * Constant values for user manual pdfs
                private static const PDF_STRING:String = "blahblahblah.pdf";
                private function init():void
                    /* Define file reference object and add a bunch of event listeners. */
                    fileRef = new FileReference();
                    fileRef.addEventListener(Event.COMPLETE, completeHandler);
                    fileRef.addEventListener(Event.OPEN, openHandler);
                    fileRef.addEventListener(ProgressEvent.PROGRESS, progressHandler);
                private function doEvent(evt:Event):void
                    /* Create shortcut to the FileReference object. */
                    var fr:FileReference = evt.currentTarget as FileReference;
                    try
                        /* Update the Model. */
                        fileRefModel.creationDate = fr.creationDate;
                        fileRefModel.creator = fr.creator;
                        fileRefModel.modificationDate = fr.modificationDate;
                        fileRefModel.name = fr.name;
                        fileRefModel.size = fr.size;
                        fileRefModel.type = fr.type;
                        /* Display the Text control. */
                    catch (err:*)
                        /* uh oh, an error of sorts. */
                private function downloadPDF(url:String):void
                    /* Begin download. */
                    urlReq = new URLRequest(url);
                    fileRef.download(urlReq);
                 * When the OPEN event has dispatched, change the progress bar's label
                 * and enable the "Cancel" button, which allows the user to abort the
                 * download operation.
                private function openHandler(event:Event):void
                    downloadStatusContainer.visible = true;
                    downloadStatusContainer.includeInLayout = true;
                    downloadProgressBar.label = "DOWNLOADING %3%%";
                    cancelButton.enabled = true;
                 * While the file is downloading, update the progress bar's status.
                private function progressHandler(event:ProgressEvent):void
                    downloadProgressBar.setProgress(event.bytesLoaded, event.bytesTotal);
                 * Once the download has completed, change the progress bar's label one
                 * last time and disable the "Cancel" button since the download is
                 * already completed.
                private function completeHandler(event:Event):void
                    downloadStatusContainer.visible = false;
                    downloadStatusContainer.includeInLayout = false;
                    downloadProgressBar.label = "DOWNLOAD COMPLETE";
                    cancelButton.enabled = false;
                 * Cancel the current file download.
                public function cancelDownload():void
                    fileRef.cancel();
                    downloadProgressBar.label = "DOWNLOAD CANCELLED";
                    cancelButton.enabled = false;
                    downloadStatusContainer.visible = false;
                    downloadStatusContainer.includeInLayout = false;
            ]]>
        </mx:Script>

    The tick counter has a resolution of 1 ms.  Resolution, accuracy, and the responsiveness of the OS are three different things.  The issue is that OS latency can be 10s of milliseconds or occasionally longer.  If the OS decides to index the hard drive between the time you read the tick count and send the start audio command, your tone could be quite late. Sending the TTL pulse is a third call to the OS.  So you have two latency times for each trial. Unless you have a real-time operating system, this latency issue will introduce randomness into your data.
    Try sending TTL pulses of 50 ms duration every 200 ms, software timed, for a few minutes and look at the variation in the edge timing.  Then try it again with tones thrown into the mix and see if the variation changes. 
    That is where hardware timing and synchronization pays off. 
    Lynn 

  • How do you animate a title placed over video clip

    I have been trying to animate a still title that I have placed over a video clip in expert view.  There is only one line.  I have followed the following which I think I got from the Adobe site: 
    Create a title with animated text
    You can easily apply a preset animation to any still title. Text animation presets quickly and easily
    animate the characters in your title so that they fade or pop characters into view, or fly in from the
    top or bottom of the screen. For example, using the Fade In By Characters preset instantly makes
    each separate character in your title fade into view until the title is complete.To preview an
    animation, position the pointer on the Animation tab in the Adjust panel.
    1. Do one of the following:
    In the Quick view timeline, select the superimposed clip. In the Monitor panel, click the clip,
    and then double-click the title text.
    In the Expert view timeline, double-click the title clip.
    The Adjust panel changes to display the text options.
    2. In the Adjust panel, select an animation preset under the Animation tab.
    3. Do one of the following to apply the preset to the title:
    Click Apply.
    Drag the preset to the Monitor window and drop it on top of the title text
    I have had no success no matter what I've tried.  I have a mac.  I would value any suggestions.
    Thanks.
    barb

    SG
    Thanks. But let me clarifiy what I suspect Barb's issue is
    a. not selecting the Text in the Text section of the Titler before applying the animation in Animation section of the Titler.
    or
    b. what I did not yet write, not using Default text since Text Animation does not work with Default crawl or roll
    or
    c. trying to use more than one line of text without the use of special procedures.
    (I sort of put this thought aside when I replied since Barb wrote
    I have been trying to animate a still title that I have placed over a video clip in expert view.  There is only one line.
    I interpreted that as only one line of text was typed in the Titler, not that there were two lines of text types.
    But, the answer should be one of the 3. More details from Barb should help us to pin point the problem.
    I think it was JohnnyO who first pointed out (your forum at few years back) that you can indeed apply Text Animations to more than one line of text in Premiere Elements Titler, but with the use of special maneuvers. I wrote about this and did a detailed step by step and overview on the matter.
    ATR

  • How do you move iMovie 09 files over to another Mac?

    I am trying to move my entire collection of imported movies and 2 projects to my larger computer. I have saved all the files in my iMovie folder on my MacBook Pro onto an external hard drive. When I try to import them onto my MacPro I get an error message that says there is nothing to import even though there are over 122GB of iMovie files on the drive. When I try to import just the projects they are unable to be selected. I am running the same version of iMovie on both computers.
    Thanks

    If you find that the HomePage sites don't work correctly in the new location put them back and then just link to them from an iWeb site. They can be anywhere.
    OT

Maybe you are looking for

  • Question about the performence of Java Card

    Could anyone here tell me how slow running algorithms, like rc4�Ades3 or rsa, on an 8k EEPROM JavaCard? thanx in advance rong

  • PI on IDOC to CIDX

    Dear All, I just managed my configuration of PI for B2B (IDOC - CIDX). I am using "Business System without party for SAP ERP IDOC" and  "Communication component with Party for CIDX Adapter". I managed to send the idoc to SAP PI. I can see the message

  • Combo drop box calculation?

    I'm dont work with acrobat much so please excuse my lack of knoweldge. I have been reading all week and have learned a lot about performing calculations. I have no issues with creating simple add and subtract etc. I have been using mostly text feilds

  • How to get around ora-ORA-04091: table SSBOSS.SSTRMAST is mutating, trigger

    hi, Does anyone know how one would get around this problem please ? Here is my dbase trig: CREATE OR REPLACE TRIGGER SSBOSS.new_not_greater_than_net BEFORE INSERT OR UPDATE OF newrent ON SSBOSS.SSTRMAST REFERENCING NEW AS new OLD AS old FOR each row

  • Difficulties with Connectivity.

    Alright. So my family and I purchased a brand new iMac a few days ago and we love it very much. We had hoped that we could get the Mac and keep our 3 year old Dell desktop, as well, so that we could have more people working at any given time. I did a