4.9 C
New York
Thursday, March 27, 2025

networking – 3 firewalls on a layer-2 swap, 1 acts as a default gateway for all units


I’m presently making an attempt to setup a community madeup of a big layer-2 swap, some computer systems related to that swap, 3 Cisco Firepower 1120 ASA Firewalls, and different networks past 2 of the firewalls, with the opposite firewall performing because the default gateway. This firewall that acts as a default gateway has the target to route any packets destined or from the networks of the opposite firewall. Under is a picture of the community:

juandcc2014_1-1743044358874.png

I’m simulating the community I’ve bodily with what I’ve on Packet Tracer. So as an alternative of utilizing a Firepower 1120 ASA, I’m suing a 5506-X firewall. Every laptop on the 192.168.1.0 community(ex: Desktop 0) has 192.168.1.254 as its default gateway.

So, if I need to ping from Desktop 0 to Community 4 PC, the packet would first go to the Default Gateway Firewall(DG FW), then to Community 4 ASA FW, then to Community 4 Router, then to Community 4 L2 Change, then to Community 4 PC, and lastly get hold of the ping reply coming the identical means it got here in. The Default Gateway Firewall must also handle receiving and giving its ping replies to the desktop.

— Details about units —

— Conduct —

When pinging:

  • Solely Desktop 1 efficiently pings Community 1 PC and Community 2 PC, following the right path said initially
  • Desktop 0 and a pair of have unusual habits I don’t perceive:
    • When Desktop 0 or 1 Pings Community 4 PC, the Simulation view reveals the ICMP packet going straight into Community 4 ASA FW somewhat than going to DG ASA Firewall. The ping will get again efficiently to Desktop 0 but it surely clearly didn’t observe the supposed path(DG ASA Firewall first, thenNetwork 4 ASA FW)
    • When Desktop 0 or 1 Pings Community 1 PC, the Simulation view reveals the ICMP packet going once more straight into Community 4 ASA FW however this time it would not ship it to the router, it sends a packet again to the swap, which the swap sends to the Desktop 0, and the Final Standing column signifies Failed on the ping

I’m pretty new to networking so any assistance is appreciated.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles