Firewalling 2 live WAN links

Sep 04, 2007 1 Replies

I currently have one ASA 5510 sitting behind one of my edge routers and I'd like to also use this same device to firewall another WAN link. Currently the 2 networks behind each WAN link can talk to each other through our core router. Is this doable? Would I need to configure 2 inside interfaces so that traffic destined for either of those WANs have their own gateway? Can this be accomplished with just one inside interface? The end result will look something like this (Ip ranges are just examples):


10.1.1.0/24 WAN B = = Router B = = ASA 5510 = = Router A = = WAN A 20.1.1.0/24 = = Core Router
192.168.1.0/24 Internal Network

It's all static routing here.



Here is an example of what my current network looks like (IPs are just examples):

WAN B = = Router B = = ASA 5510 = = Core Router = = Router A = = Wan A = = Internal Network

WAN B network 192.168.10.0/24 WAN A network 192.168.20.0/24 Internal network 192.168.30.0/24

On the core router I have static routes to forward traffic destined for WAN A to Router A and traffic to WAN B to the ASA 5510. On the ASA I have routers set to forward all traffic coming out of the outside i/ f to Router B and all traffic from the inside i/f to the core router. Simple stuff. However now I want to move that Router A link up to the ASA 5510 so that both are firewalled.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required