techy32 Posted October 17, 2019 Posted October 17, 2019 We are currently using internal Cisco ASA firewall and moving to external firewall during the half term. The new firewall is Juniper hardware which is installed for our broadband. The company will do all the configuration on their Juniper firewall side but we need to carry out work on our HP core switch to remove the existing connection to ASA firewall and route to Juniper firewall. Can anyone explain what actually we are doing in terms of removing the connection to ASA and routing the connection to Juniper firewall on HP core switch (is it removing static route on the particular port and adding a new route to the juniper firewall?).
mavhc Posted October 17, 2019 Posted October 17, 2019 Your devices should have a gateway ip/default route, that's what needs changing. If everything's going the HP core switch as its gateway, then just change the gateway there. 1
techy32 Posted October 17, 2019 Author Posted October 17, 2019 Your devices should have a gateway ip/default route, that's what needs changing. If everything's going the HP core switch as its gateway, then just change the gateway there.Thank you for the reply. Yes the connection goes to our core switch from internal firewall. Could you point me to the tutorial on a website which explains it step by step.... Sorry I am new to firewall/core switch.....
techy32 Posted October 17, 2019 Author Posted October 17, 2019 What model is your core switch?HP 8206zl
mrbios Posted October 17, 2019 Posted October 17, 2019 change the static 0.0.0.0 route to point at the IP of the new firewall. If you do "show ip route" you'll most likely have a 0.0.0.0 rule which currently routes traffic to your ASA IP. That is assuming IP routing is enabled, which is likely. Otherwise you'll just be changing the default gateway on the 8206, but in all likelihood you've got ip routing enabled so you'll need to change the 0 route.
techy32 Posted October 18, 2019 Author Posted October 18, 2019 change the static 0.0.0.0 route to point at the IP of the new firewall. If you do "show ip route" you'll most likely have a 0.0.0.0 rule which currently routes traffic to your ASA IP. That is assuming IP routing is enabled, which is likely. Otherwise you'll just be changing the default gateway on the 8206, but in all likelihood you've got ip routing enabled so you'll need to change the 0 route.I will check and update. Thank you
techy32 Posted October 21, 2019 Author Posted October 21, 2019 Here is the screenshot.... We do have IP routing enabled and the rule 0.0.0.0/0 is pointing to ASA firewall's IP address. Can you please guide how to change this IP address? Thank you
mavhc Posted October 21, 2019 Posted October 21, 2019 ftp://ftp.hp.com/pub/networking/software/8200zl-MgmtCfg-Sept2007-59918583.pdf Page 8.5 shows how to do it from the text menu. ssh/telnet in, then type menu. But first find out how to backup the current config. 1
techy32 Posted October 24, 2019 Author Posted October 24, 2019 All sorted. Thank you very much for your help
MS2011 Posted October 24, 2019 Posted October 24, 2019 We are currently using internal Cisco ASA firewall and moving to external firewall during the half term. The new firewall is Juniper hardware which is installed for our broadband. The company will do all the configuration on their Juniper firewall side but we need to carry out work on our HP core switch to remove the existing connection to ASA firewall and route to Juniper firewall. Can anyone explain what actually we are doing in terms of removing the connection to ASA and routing the connection to Juniper firewall on HP core switch (is it removing static route on the particular port and adding a new route to the juniper firewall?). Can I ask why did you moved from Cisco ASA to juniper? We have ASA in place as well.
techy32 Posted October 25, 2019 Author Posted October 25, 2019 Our ASA firewall is an old box with the limitation of 100 MB and we looked into replacing the firewall which was costing a bit. A managed firewall was included in our broadband contract and we went with it without spending anything. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now