Steve21 Posted October 24, 2016 Posted October 24, 2016 Morning All, Finally getting some time to try to sort out the current setup of the routing/gateways here since I've started not had a proper dig in it and can't for the life of me work out if I'm missing something or whether this is setup oddly. Now from my understanding the normal two options is either Router on a stick, and then all the internet/firewalls would plug into a switch, or if you're using your router as the core then everything would plug into that. This is the current setup and how it seems to be attached and can't work out why someone would have done it this way around. So a computer at the bottom, lets say on VLAN 30. Connects to it's HP switch and is linked back to the HP chassis. This then goes over the trunk (The 3 orangeish cables) to the Cisco router for routing (Now VLAN 10). All good so far. Now if it was internal traffic it'd get routed back across the trunk to the chassis, again all good. However if it's internet traffic it's getting routed back along the trunk (orangeish) to the HP chassis, which is then going over the purple to the firewall. (It's not a sonicwall but couldn't find smoothie pic), this is then routed out the Smoothwall as external traffic back into the Cisco router (red), and off via Green to our ISP Juniper router and into the internet. What I don't understand unless I'm missing an obvious is either a) Why red doesn't go straight to the Juniper thus removing the green, and no need to go back to the Cisco router. or b) The Cisco Router doesn't route direct to the firewall (so move the purple to the router). Thus removing the need for traffic to re-use the trunk/chassis again? Just seems to be re-looping a few times and thus not actually securing anything really, as inwards traffic via the firewall has to go through the router first, and outwards traffic shouldn't need routing? Now to expand the story, basically I'm trying to re-design our wireless a bit to make it easier for conferences etc to connect without needing to worry about AD credentials etc etc. So I'm trying to make a new VLAN that bypasses our filtering, and doesn't touch the main network. The problem I'm having is with the current setup I can't see a way that I can have transparent proxy enabled (thus needing to go via Smoothwall), but bypassing the Cisco Router. (The only way I could see of doing this if Smoothwall even supports it, would be the new VLAN goes direct to the Smoothwall on a new Port (Say 2), this has DHCP enabled on, and is then routed out a new port (say 3) direct to the Juniper. Thus not touching the main network at all? Surely should be easier way ) Hope that makes sense, but shout if you need clarification at all Thanks, Steve
bob_uk2k Posted October 24, 2016 Posted October 24, 2016 Hi Steve, That Cisco almost seems to be there for the sake of being there. I would suspect you can do all internal vlan routing within the HP chassis with IP routing enabled and assigning IP addresses to the vlans. I can only imagine the Juniper goes the to Cisco for a local breakout of another network is the Juniper has maybe an extra voip vlan or something like that on it otherwise it could probably plug direct. I generally have a gateway vlan on the core switch that the firewall nic plugs into and then I'd add a vlan interface on to the smoothwall that matches the boyd vlan id on the core switch so that it's only switched by the internal switching. Robert
MicrodigitUK Posted October 24, 2016 Posted October 24, 2016 When that Cisco router was first installed it only had a 3 gig trunk and no extra module for internal VLAN routing. The reason it was not all done on the HP routing is because the Cisco allowed complex ACLs for internal routing and also NAT (it was originally just on the HP). Looks like someone has installed the module afterwords and not fully understood that's why you now have all the extra connections between the module everything else. Suspect it was that interim contractor. If it helps Steve, I'v got the same router at my new place and a Smoothwall with 802.1X running BYOD on a secure VLAN protected with ACL. Pop over the other end of town and I'll go over my config. Might give you some ideas for your reconfigure job. To much to put down into words on a thread.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now