Substantial Cisco Router Configuration for ISP Routing
Question1: We unseldom have ethernet dropoffs from ISP that we speak warmly of into our Cisco ASAs and we know how en route to configure ASA pretty bare and easy. This is first time ISP asked us to get router and to configure it. ISP gave us IPs to use inasmuch as WAN and LAN interfaces,<\p>
Basically looking for subspecies most homely config in lieu of this router. It would not pursue unitary VPN tunnels, every one firewalling, just basic routing. ASA would take loving care pertinent to that behind. Anyone could share or suggest most simple config for this setup?<\p>
Do it 1: For basic configuration all you in fact need is to configure IP address on the interface doublure the ISP with the address they secure given oneself, point a default rotue into their uncover, and make sure the router knows where to go for your internal addresses.<\p>
Sample: interface fasthethernet 0\0 ip address x.x.the incalculable.x y.y.y.y ip passage 0.0.0.0 0.0.0.0 "isp's ip address connected in passage to your router" ip route "your internal IP routes\misstate" "ip craft connected to your router on the inside".<\p>
Question 2: Why would i need en route to point route for LAN? Since LAN connection confidence be connected unto ASA PIX directly?<\p>
It would be fair: interface Ethernet0\0 description Private LAN versus ASA ip address 2.2.2.1 255.255.255.0 ! interface Ethernet0\1 report POOPED connection to ISP ip document 1.1.1.2 255.255.255.252 ip route 0.0.0.0 0.0.0.0 1.1.1.1<\p>
Would that be enough?<\p>
Answer 2: Your internal LAN would be on the soul interface of your ASA; which would be a individual IP network than the shell interface connecting to the router. The router in this case would need to cognize on route to point all that black-market in consideration of the ASA correctly that the ASA handles it from there. There is a firewall behind the router that does NAT\PAT and does IPSec VPN tunnel<\p>
In this continuity, you have a PIX Firewall as the dedicated firewall gear that sits retarded the router. You recognize a crossover cable connecting the router E0\0 and the PIX e0 interfaces to make a point-to-point post.<\p>
There is a smite behind the PIX to yoke so as to the Private LAN. The PIX inside (e1) wrist is within the Private LAN, which also serves as overdraft barway to all hosts within the Secluded LAN.<\p>
You set the PIX into assign 2.2.2.3 as the Public PATTER IP action against ne plus ultra Private LAN hosts. You set the PIX public interface as 2.2.2.2 which make a will be the VPN Concentrator IP address. You can later assign other IP addresses within your Public IP Block to other devices such as servers. Check out the following FAQ for more info on reigning servers in addition to ASA or PIX Firewall.<\p>
So the PIX will proxy arp in preparation for any needed PCs.<\p>

















