How to configure switch to route ISP ethernet handoff? (L3 or VLAN routing)

I have an ISP providing a redundant internet circuit through Ethernet handoff, and I need to route their border network to my firewall which will hold the public IP address block.  The handoffs will go into 2 3750 switches stacked, which in turn will be uplinked to an ASA active/standby pair.  How do I configure the switches to handle the traffic?  The equipment isn't in place yet so I can't test the configuration; just trying to validate the plan.  I'm not sure of the pros/cons of using L3 switchport vs VLAN routing.
Example, ISP provides 2 drops, 10.10.10.1/29 and 10.10.10.2/29, and a virtual gateway to route traffic out to the internet, 10.10.10.3/29 (FYI - in reality these are public IP's, just using privates for example).  Assume the public block is 192.168.0.0/24.  I need to configure the 3750 switches with interfaces of 10.10.10.4/29 and 192.168.0.1/24.  The ASA firewall outside interface will be 192.168.0.2/24.
The ISP routes everything destined for 192.168.0.0/24 to 10.10.10.4/29.  I need to route all outbound internet traffic to 10.10.10.3/29.
So the 3750 would have a layer 3 port-channel with IP 10.10.10.4/29 to uplink to the ISP drops.  It will also have another layer 3 port-channel with IP 192.168.0.1 (or should I use a VLAN interface for both or either?).  The ASA outside interface will be 192.168.0.2.  On the ASA my default route out is 0.0.0.0 0.0.0.0 192.168.0.1.  The default route on the 3750 stack will be 0.0.0.0 0.0.0.0 10.10.10.3.
Thoughts?
                                                                             [ISP-BORDER1-10.10.10.1]
[INTERNET]----[ISP-BORDER-VIP-10.10.10.3]                                                 [3750-L3-PORT-10.10.10.4/192.168.0.1]----------[ASA-192.168.0.2]
                                                                            [ISP-BORDER2-10.10.10.2]

Hi,
Any update on above queries.
Need Solution.

Similar Messages

  • How to configure network with just 1 ethernet adapter?

    I was looking for a guide which would talk about how to configure your network in case if you have only 1 Ethernet adapter. Is it mandatory to have more than 1 network card to configure multiple ports? If not, what are the options available to deploy a Virtual Machine that can have applications which are available over the network. I don't have a separate network i.e. public network as well as management network is of same IP range.
    I am having 2 node cluster using NFS for pools as well as repository.
    ~Yagnesh

    yagneshg wrote:
    I was looking for a guide which would talk about how to configure your network in case if you have only 1 Ethernet adapter. Just enable the "Virtual Machine" role on the Management network that is automatically connected. You will then be able to add guest vNICs to the same network.
    I am having 2 node cluster using NFS for pools as well as repository. I strongly recommend you get at least one more physical NIC for your server, if not two: running NFS and the cluster heartbeat and the guest traffic all over the same network is going to put a lot of data down the wire and you may land up in a situation where the cluster traffic is overwhelmed and a node reboots. You need to be very careful in this situation. Network cards are cheap and you should have at least two or three, I reckon.

  • How to configure WRT54GL as router only?

    I already have a linux server doing all the routing for my internet connection. I just wanted to add Wireless access for wireless devices i just bought. So, i want to configure this wrt54gl only as wireless router.
    So, I configure this wrt54gl as router mode. I connected this port 1 wrt54gl into my existing wired switch. I configure the wrt54gl to account lan IPs of 192.168.10.200 to 250. When I try to connect my wireless notebook, it can connect and get the IP. But problem is the notebook get gateway of wrt54gl. How can I make this wrt54gl to give out my real gateway, 192.168.10.1???
    My linux server is the real gateway with IP 192.168.10.1
    WRT54GL ip is 192.168.10.100
    Do I need to connect the lan into the internet port instead?

    Perhaps this is something to do with Setup --> Advanced Routing --> Static Routing??
    I don't know what value to fill up. I tried just now and it caused routing problems. I had to reset the router to factory default and configure the thing again.
    Appreciate any feed back.

  • How to configure Gennic for router?

    I have installed UCCE 9.0. How do I install and configure gennic NIC for the router? The gennic.exe process shows state start pending and waiting. When I go in config manager - > nic explorer and try to add nic I dont see the gennic type there. I only see available NIC as in the attached screenshot.
    Events from August 31, 2012:
    15:54:33:695 ra-nica Initializing Event Management System (EMS) Library.
    15:54:33:696 ra-nica Trace: EMS Server pipe ucc9\RouterA\nicaEMSPipe enabled for ucc9\RouterA\nica
    15:54:33:697 ra-nica Initializing Node Manager Library.
    15:54:33:697 ra-nica Generic NIC process initializing.  Release 9.0.1.0 , Build 1447.
    15:54:33:698 ra-nica Trace: Monitor Server pipe ucc9\RouterA\nicaCmdPipe enabled for ucc9\RouterA\nica
    15:54:33:702 ra-nica Trace: EMT I/O completion ports: max threads=4, concurent threads=0
    15:54:33:710 ra-nica Trace: MBufLimitMgr OpenMutex Global\MBUF Limit Table Mutex
    15:54:37:307 ra-nica Connection to MDS process established.
    15:54:37:311 ra-nica Trace: Elective Overload control file not loaded
    15:55:03:860 ra-nica MDS is in service.
    15:55:03:874 ra-nica INRCEngine (DeviceID=5000) CONFIGURE_NIC_RESP error.  error=1
    15:55:13:851 ra-nica INRCEngine (DeviceID=5000) CONFIGURE_NIC_RESP error.  error=1
    15:55:23:852 ra-nica INRCEngine (DeviceID=5000) CONFIGURE_NIC_RESP error.  error=1

    After speaking to Steve Hartman, I found that Nic is not needed for ICM CIM integration. So ignoring that error.

  • How to configure switch boxes in VHDL in Virtex-5 device?

    Hello,
    I am wondering if there is a way to cobfigure switch boxes in VHDL, initialize them and connect them consecutively as you wish? I want to connect a series of switch boex together (the output of first is the input of the next), but I do not know is it possible through VHDL or not?
    I thank in advance for any kind help and assist.
    Regards,

    m,
    The carry chain has typically been used in the past to create a programmable fine grained delay line.
    Programming interconnect to do that is hard, and results in unpredictable delay, large variation, and a variation in step size.
    I would not recommend it.
     

  • How to configure ECM for routing

    Friends
    I need to make Change Number as mandatory for transaction CA02. I am trying to make field Change Number as required field in transaction OP5a/b, but it is either making mandatory to CA01/CA02 and even CA03 or nothing is happening.
    I will appreciate if  some one can gyide  me  the correct steps for making chnage number as mandatory for CA02 only will be great

    Dear,
    For activating the change number as mandatory. Do following things
    Go to OP5A -> PP task list: initial screen -> Change number-> Modified -> Transaction code select required radio button and save it.
    Check and revert back
    Regards / US

  • HT4259 how to configure extended network via ethernet

    how to configure an extended network via ethernet

    I assume that the Express is new, so that it still has the factory default settings.
    Connect an Ethernet cable from one of the LAN <-> ports on the AirPort Extreme to the WAN "O" port on the AirPort Express
    Power up the Extreme and Express if they are not already powered up
    Open Macintosh HD > Applications > Utiltities > AirPort Utility
    Click on the tab in the upper left hand corner of the window that reads Other AirPort Base Stations (1)
    Click on the AirPort Express xxxxxx
    Wait a minute or two while AirPort Utility analyzes the network and then announces that the Express will be configured to extend your network
    Enter a name for the AirPort Express and click Next
    Wait 2-3 minutes while AirPort Utility configures the Express and the Express restarts
    When you see the message that setup is complete, click Done
    That's it.

  • DHCP Server Configuration - Cisco 1750 router

    Good Day All,
    can anybody give me a step by step procedure on how to configure my 1750 router as a DHCP server?
    Thank you,
    Lester

    Hello Moses,
    You do InterVlan routing with your router, Fa0/1 and Fa0/0 is on your router, two different subnets with two different pools. From the router you have two uplinks - access links. These links are terminated on two different Layer 2 vlan on the switch. If Fa0/0 is terminated on vlan 100, hosts in vlan 100 will get IP address from Fa0/0's dhcp pool, if Fa0/1 is terminated on vlan 200 on the switch all hosts will get ip from Fa0/1's address space.
    Fa0/0 dhcp pool: address of the interface is in the pool
    Fa0/1 dhcp pool: address of the interface is in the pool, interface address is member of the subnet (that's will be the GW)
    bye
    FCS
    Please rate me if I helped.

  • Connecting two WRT54G wireless routers - how to configure

    Hi All,
    I have two WRT54G wireless routers. One is currently providing wireless access for several users at a local law firm. I need to connect a second wireless router for a user who works for another company in the same office. The second wireless router is basically going to be used for Internet access. The Office Manager at the law office does not want the user from the other company using their wireless router directly, BUT they will allow me to hook up the second wireless router for Internet access. I realize this doesn't really make sense in terms of security, but this is the scenario I must abide to. So I am wondering how to configure the second router. I am thinking that I connect a CAT5 from one port on the first router to the Internet port on the second router. I am also guessing that I need to assign the the second router a static IP with a different subnet such as 192.168.2.1. I am not sure if the first router still has the default 192.168.1.1. If the first router does use 192.168.1.1 would I need to change the IP on the second one to one on another subnet? Thanks.

    You will need a setup like this:
    Modem  ---  new WRT54G  ----  existing WRT54G
                     192.168.2.1              192.168.1.1    ( "Local IP address" )
    Modem connects to Internet port of new WRT54G.
    LAN port of new WRT54G connects to Internet port on existing WRT54G.
    SSID:  different on each router  (do not use "linksys" )
    SSID broadcast:  enabled on both routers
    encryption:  recommend WPA2, or at least WPA  (can be same or different on the two routers).
    passwords:   different on each router.
    channel:  try to stay at least 5 channels apart.  Usually channel 1, 6, and 11 work best, but any two different channels can be used.
    Any "port forwarding" used by existing WRT54G must also be done on new WRT54G.
    Both routers need a real login password (not "admin" )
    New WRT54G will need "Intenet connection type" set to whatever is currently on existing WRT54G.  Internet connection type for existing WRT54G will need to be set to DHCP.
    Message Edited by toomanydonuts on 01-15-2008 01:54 AM

  • Pa-mc-8te1 can i use this a ethernet POrt how to configure it ...

    pa-mc-8te1 can i use this a ethernet POrt how to configure it ...

    Hi Venkat,
    Please ask this question in routing/switching forum. As far as i know you can only configure pa-mc-8te1 as E1 or T1 ports. For more details please visit the below link.
    http://www.cisco.com/c/en/us/td/docs/interfaces_modules/port_adapters/install_upgrade/multichannel_serial/8-port_multichannel_t1-ei_8pri_install_config/8port_t1/2738ovr.html
    Regards,
    Kanwal
    Note: Please mark answers if they are helpful

  • ASA 5505 8.4. How to configure the switch to the backup channel to the primary with a delay (ex., 5 min) using the SLA?

    I have ASA 5505 8.4.  How to configure the switch to the backup channel to the primary with a delay (for example 5 min.) using the SLA monitor?
    Or as something else to implement it?
    My configuration for SLA monitor:
    sla monitor 123
     type echo protocol ipIcmpEcho IP_GATEWAY_MAIN interface outside_cifra
     num-packets 3
     timeout 3000
     frequency 10
    sla monitor schedule 123 life forever start-time now
    track 1 rtr 123 reachability

    Hey cadet alain,
    thank you for your answer :-)
    I have deleted all such attempts not working, so a packet-trace will be not very useful conent...
    Here is the LogLine when i try to browse port 80 from outside (80.xxx.xxx.180:80) without VPN connection:
    3
    Nov 21 2011
    18:29:56
    77.xxx.xxx.99
    59068
    80.xxx.xxx.180
    80
    TCP access denied by ACL from 77.xxx.xxx.99/59068 to outside:80.xxx.xxx.180/80
    The attached file is only the show running-config
    Now i can with my AnyConnect Clients, too, but after connection is up, my vpnclients can't surf the web any longer because anyconnect serves as default route on 0.0.0.0 ... that's bad, too
    Actually the AnyConnect and Nat/ACL Problem are my last two open Problems until i setup the second ASA on the right ;-)
    Regards.
    Chris

  • How to Configure Transparent caching on Cat 6500 with CSM in routed mode

    I am trying to configure Transparent caching on Cat 6500 with CSM in routed mode, but facing some problems in it , also I have gone thru the example config on cisco site for transparent caching using CSM on Cat 6500 , but the above does not fit my clients requirement.
    The scenario is like
    Access Switches - Cat6500 with MSFC & CSM - Internet Router
    |
    Cache Engines and Real servers
    The clients as well as real servers are on seperate VLANs (L3) and the requirement is to load balance the internet traffic using cache engines.
    I'd really appreciate any helpful suggestions or any useful links/docs/info on this.
    Thanks
    kumar

    Hello Joerg,
    Thanks for the reply.
    I have already gone thru the sample config shown by this weblink, however this link refers to configuring transparent caching on the CSM in BRIDGED MODE ( i.e both the client and server vlans are having the same IP address ) but in our case , we have multiple L3 VLANS on the CAT6509 having IP addresses in different SUBNETS , and the Real servers to be used for caching also exist on one of these VLANS. Thus, the scenario described by the Weblink does not apply here. Also , in the configuration referred by the above weblink, the VLAN 100 is configured as client , however the endusers are shown to be on vlan200 which is configured as SERVER VLAN in the CSM.
    Dont you think there is something wrong here, I mean the endusers should be on VLAN 100 (Client) and real servers on VLAN 200 (SERVER).
    So, I have to configure CSM in routed mode ( i.e both the client and server vlans will have seperate IP addresses in different subnets ) and the endusers will be on all VLANS .
    Pls let me know , how I can implement this solution.
    Thanks again
    Sudhir

  • Airport Express as "Ethernet-Bridge" for old iMac - how to configure WPA?

    Hi,
    I have a very old iMac G4, which up to now was connected to my network via a Netgear wireless bridge. As I switched my router to a Fritzbox, which supports N-Draft I wanted all network clients to use N-Draft, so I bought the new AX.
    It works ok as an Ethernet bridge when configuring the wireless part to "connect to a wireless network", "allow ethernet clients" and no encryption.
    I am now online with that configuration.
    But when I activate either WEP, WAP, WAP&WAP2 encryption on my Fritzbox router and then in the Airport Express it won't get an IP-address via DHCP anymore. It can connect to the wireless network, but via the ethernet connection it does not assign ip-address anymore.
    I already tried assigning the IP-address manually. The light on the AX is green, but DNS does not resolve, although I also entered the DNS server of my provider manually.
    Any idea? Is it perhaps just not possible the use the ethernet port if the wireless connection is encryted?
    Regards,
    Jörg

    Hi again,
    I can answer my question now: my router (Fritzbox) and the Airport Express can only communicate with ONE kind of encrytion - only via WAP2.
    WEP does not work, WAP does not work, WAP/WAP2 does not work.
    But at least now I have a complete N-Draft Network with good encrytion. It only cost me 4 evenings of long trial & error configurations.
    Hope I can at least help others,
    Jörg

  • How to configure GlobeSurfer II umts modem router to act as just a modem

    Sorry if this has been asked before but after three days of searching I haven't been able to find an answer.
    I'd like to know how to configure a GlobeSurfer II umts modem router to act as just a modem allowing my TC to provide all the remaining wireless services.
    I know the combination can easily be made to work with the TC as in bridge mode but doing that loses features of the TC that I'd like retain.
    I've found a fairly comprehensive manual on line but it doesn't address my specific needs and I'm not techie enough to interpret the information that's provided into a work around.
    Thanks

    Hi Bob,
              many thanks for answering. GlobeSurfer suggested the following
    "the easiest is to use the Ethernet to connect the GlobeSurfer to your Capsule. Make sure that you have the 2 routers having difference IP address ranges and they don't overlap each other."
    That pretty much contradicted everthing I've read in discussions so I've asked for information on how to
    1. stop the GlobeSurfer from acting as DHCP and stop it providing IP addresses
    2. make the GlobeSurfer a client of the Time Capsule
    I was already using an e cable between the two but in the mean time I did the rest of what they sggested. The only warning I got on the TC was a "Double Nat" for which I clicked "ignore".
    As a result I have the two networks that I wanted, (one protected with private HDDs and printer attached and one guest), I can connect to the internet through both, I've been able to extend the main using an Extreme in bridge mode and there's no sign of a third network being produced by the GSII. I'm delighted and I'm stunned to say that it worked.
    It'll be interesting to hear what they come back with.
    Thanks again

  • How does a switch learn its route

    Hi
    I have a cisco switch and somehow it finds the best route through different routers, I tested this with traceroute from the switch. How does the switch learn these routes?
    Thanks
    Dan

    Hi Rick
    Thanks for the info. My switch is a 3500 layer 2 switch. Here's the config for my switch:
    Current configuration:
    ! Last configuration change at 16:04:28 GMT Wed Mar 15 2006
    ! NVRAM config last updated at 09:49:35 GMT Wed Apr 27 2005
    version 12.0
    no service pad
    service timestamps debug uptime
    service timestamps log uptime
    service password-encryption
    hostname switch1
    enable secret 5 ttttttttttt
    clock timezone GMT 1
    ip subnet-zero
    ip name-server 10.11.10.2
    ip name-server 10.11.10.1
    cluster enable l3 0
    cluster member 1 mac-address 0007.ebc9.9380
    cluster member 2 mac-address 0007.ebc9.94c0
    cluster member 3 mac-address 0007.853f.6d00
    interface FastEthernet0/1
    switchport access vlan 102
    interface FastEthernet0/2
    duplex full
    speed 100
    port monitor FastEthernet0/8
    switchport access vlan 110
    interface FastEthernet0/3
    switchport access vlan 102
    interface FastEthernet0/4
    switchport access vlan 102
    interface FastEthernet0/5
    port monitor FastEthernet0/19
    port monitor FastEthernet0/22
    switchport access vlan 100
    interface FastEthernet0/6
    switchport access vlan 101
    interface FastEthernet0/7
    duplex full
    speed 100
    switchport access vlan 102
    interface FastEthernet0/8
    duplex full
    speed 100
    switchport access vlan 110
    interface FastEthernet0/9
    duplex full
    speed 100
    switchport access vlan 102
    interface FastEthernet0/10
    duplex full
    speed 100
    switchport access vlan 102
    interface FastEthernet0/11
    duplex full
    speed 100
    switchport access vlan 102
    interface FastEthernet0/12
    switchport access vlan 101
    interface FastEthernet0/13
    switchport access vlan 102
    interface FastEthernet0/14
    duplex full
    speed 100
    port monitor FastEthernet0/23
    switchport access vlan 102
    interface FastEthernet0/15
    duplex full
    speed 100
    switchport access vlan 102
    interface FastEthernet0/16
    duplex full
    speed 100
    switchport access vlan 108
    interface FastEthernet0/17
    duplex full
    speed 100
    switchport access vlan 108
    interface FastEthernet0/18
    duplex full
    speed 100
    switchport access vlan 102
    interface FastEthernet0/19
    duplex full
    speed 100
    switchport access vlan 100
    interface FastEthernet0/20
    duplex full
    speed 100
    switchport access vlan 108
    switchport trunk encapsulation dot1q
    switchport trunk native vlan 108
    switchport mode trunk
    interface FastEthernet0/21
    duplex full
    speed 100
    port monitor FastEthernet0/7
    switchport access vlan 102
    interface FastEthernet0/22
    switchport access vlan 100
    interface FastEthernet0/23
    duplex full
    speed 100
    switchport access vlan 102
    no cdp enable
    interface FastEthernet0/24
    switchport access vlan 102
    interface GigabitEthernet0/1
    switchport trunk encapsulation dot1q
    switchport trunk native vlan 102
    switchport mode trunk
    interface GigabitEthernet0/2
    switchport trunk encapsulation dot1q
    switchport trunk native vlan 102
    switchport mode trunk
    interface VLAN1
    no ip address
    no ip directed-broadcast
    ip nat outside
    shutdown
    interface VLAN102
    ip address 10.11.8.21 255.255.248.0
    no ip directed-broadcast
    ip nat outside
    ip nat inside source list 199 interface VLAN102 overload
    logging facility local6
    logging 10.11.9.21
    logging 10.24.21.1
    access-list 199 dynamic Cluster-NAT permit ip any any
    banner motd ^C
    Switch 1
    ^C
    line con 0
    password 7 xxxxxxxx
    transport input none
    stopbits 1
    line vty 0 4
    exec-timeout 35000 0
    password 7 xxxxxxxx
    login
    line vty 5 15
    password 7 xxxxxxxx
    login
    ntp clock-period 11259714
    ntp server 10.11.9.21
    end
    I haven't got a default gateway, any idea how its finding its route?
    Thanks again
    Dan

Maybe you are looking for