Skip to main content

Cisco ASA Firewall Configuration (Part-2)



Cisco ASA Firewall Configuration (Part-2)
 
 OSPFv2 Dynamic IP Routing on the Cisco ASA Firewall

ကဲဒီေန႔ေတာ့ ASA Firewall နဲ႔ OSPFv2 တြဲစမ္းၾကတာေပါ့ ....
အေပၚကပုံမွာျပထားတဲ့  OSPF Configuration Commands ေတြအတိုင္း လက္ေတြ႕လုပ္ႏွိုင္ၿပီျဖစ္ပါတယ္။

Cisco ASA Firewall နဲ႔ OSPF Routing Protocol အေျခခံအနည္းငယ္ေတာ႔သိထားရမွာျဖစ္ပါတယ္။

ospfv2 verification commands for cisco asa firewall


ASA1#show interface ip brief
ASA1#show route
ASA1# show ospf interface
ASA1# show ospf neighbor
ASA1# show ospf database


Supported Routing Protocols for ASA Firewall Dynamic IP Routing

•Enhanced Interior Gateway Routing Protocol (EIGRP)

Enhanced Interior Gateway Routing Protocol (EIGRP) is an advanced distance-vector routing protocol that is used on a computer network to help automate routing decisions and configuration. The protocol was designed by Cisco Systems as a proprietary protocol, available only on Cisco routers. Partial functionality of EIGRP was converted to an open standard in 2013, is available as an IETF draft.

EIGRP is used on a router to share routes with other routers within the same autonomous system. Unlike other well known routing protocols, such as RIP, EIGRP only sends incremental updates, reducing the workload on the router and the amount of data that needs to be transmitted.

•Open Shortest Path First (OSPF)

Open Shortest Path First (OSPF) is a routing protocol developed for Internet Protocol (IP) networks by the interior gateway protocol (IGP) working group of the Internet Engineering Task Force (IETF). OSPF uses a link-state algorithm in order to build and calculate the shortest path to all known destinations. Each router in an OSPF area contains an identical link-state database, which is a list of each of the router usable interfaces and reachable neighbors.

•Routing Information Protocol

The Routing Information Protocol (RIP) is a distance-vector protocol that uses hop count as its metric. RIP is widely used for routing traffic in the global Internet and is an interior gateway protocol (IGP), which means that it performs routing within a single autonomous system.




Best Regards,
Aung Cho Htwe


Unicode Version


ကဲဒီနေ့တော့ ASA Firewall နဲ့ OSPFv2 တွဲစမ်းကြတာပေါ့ ....
အပေါ်ကပုံမှာပြထားတဲ့  OSPF Configuration Commands တွေအတိုင်း လက်တွေ့လုပ်နှိုင်ပြီဖြစ်ပါတယ်။



ospfv2 verification commands for cisco asa firewall


ASA1#show interface ip brief
ASA1#show route
ASA1# show ospf interface
ASA1# show ospf neighbor
ASA1# show ospf database

Supported Routing Protocols for ASA Firewall Dynamic IP Routing

•Enhanced Interior Gateway Routing Protocol (EIGRP)

Enhanced Interior Gateway Routing Protocol (EIGRP) is an advanced distance-vector routing protocol that is used on a computer network to help automate routing decisions and configuration. The protocol was designed by Cisco Systems as a proprietary protocol, available only on Cisco routers. Partial functionality of EIGRP was converted to an open standard in 2013, is available as an IETF draft.

EIGRP is used on a router to share routes with other routers within the same autonomous system. Unlike other well known routing protocols, such as RIP, EIGRP only sends incremental updates, reducing the workload on the router and the amount of data that needs to be transmitted.

•Open Shortest Path First (OSPF)

Open Shortest Path First (OSPF) is a routing protocol developed for Internet Protocol (IP) networks by the interior gateway protocol (IGP) working group of the Internet Engineering Task Force (IETF). OSPF uses a link-state algorithm in order to build and calculate the shortest path to all known destinations. Each router in an OSPF area contains an identical link-state database, which is a list of each of the router usable interfaces and reachable neighbors.

•Routing Information Protocol

The Routing Information Protocol (RIP) is a distance-vector protocol that uses hop count as its metric. RIP is widely used for routing traffic in the global Internet and is an interior gateway protocol (IGP), which means that it performs routing within a single autonomous system.


Best Regards,
Aung Cho Htwe




Comments

Popular Posts

ARP Address Resolution Protocol

ARP Address Resolution Protocol ဆိုသည္မွာ IETF ရဲ႕ Standard Protocol တစ္ခုပဲျဖစ္ပါတယ္။ ၄င္း ARP Protocol ကို IETF မွ RFC-826 မွာ အက်ယ္တ၀င့္ ျပဌာန္းထားပါတယ္။ ARP Protocol ဟာ Local Area Network တစ္ခုအတြင္းရွိ PC ႏွစ္လံုး အျပန္အလွန္ခ်ိတ္ဆက္ရာမွာ Network Layer Address (IP Address) မွ Datalink layer Address (MAC Address) သို႔ ေျပာင္းလဲရာမွာ အသံုးျပဳႏုိင္တဲ့ Protocol တစ္ခုပဲၿဖစ္ပါတယ္။ Computer Network တစ္ခုရဲ႕ Data အခ်က္အလက္မ်ား ေပးပို႕မွႈသေဘာတရားကို ေလ့လာရာမွာ ARP ရဲ႕ လုပ္ေဆာင္မႈကို အေသးစိတ္ နားလည္ထားလွ်င္ ပိုမိုလြယ္ကူစြာ ေလ့လာႏိုင္ပါလိမ့္မယ္။ ARP ဟာ TCP/IP ရဲ႕ Link Layer Protocol တစ္ခုျဖစ္တဲ့အတြက္ Broadcast Domain တစ္ခုအတြင္းမွာသာ အလုပ္လုပ္ႏုိင္မွာျဖစ္ပါတယ္။ ဥပမာအားျဖင့္ PC1 ဟာ PC2 ရဲ႕ IPV4 Address ကိုသိရွိၿပီး PC2 ဆီကို IP Packet တစ္ခုေပးပို႕ခ်င္တဲ့အခါ ၄င္းရဲ႕ Ethernet NIC မွတဆင့္ ေပးပို႕ရမွာျဖစ္ပါတယ္။ ထုိ႕ေၾကာင့္ ၄င္း IP Packet ကို Ethernet Frame ထဲသို႕ Data Encapsulation ျပဳုလုပ္ရန္ ႀကိဳးစားတဲ့အခါ Frame Header ထဲမွာရွိရမယ့္ Source MAC Address မွာ PC1 ရဲ႕ MAC Address ကို

DMVPN ( Dynamic Multipoint Virtual Private Network ) Part-2

DMVPN Features and Benefits  Dynamic Routing Over VPN DMVPN Network ကို တည္ေဆာက္ရာတြင္ m GRE ကို အေျခခံ၍ တည္ေဆာက္သည့္အတြက္ ၄င္း GRE VPN network(DMVPN cloud) ေပၚမွတစ္ဆင့္ EIGRP,BGP,RIPv2,OSPF စတဲ႔ routing protocols တို႔၏ routing update မ်ားကို သယ္ပို႔ႏိုင္မွာ ျဖစ္ပါတယ္။ IP Multicast Support DMVPN network ဟာ GRE ကိုအေျခခံျပီး တည္ေဆာက္ႏိုင္ေၾကာင္း ကၽြန္ေတာ္တို႔သိခဲ့ျပီးျဖစ္ပါတယ္။ GRE ဟာ IP multicast packet ေတြကို သယ္ေဆာင္ေပးႏိုင္တဲ့အတြက္ DMVPN network ေပၚကေန multicast traffic ေတြကို သယ္ေဆာင္ေပးႏိုင္မွာပဲျဖစ္ပါတယ္။ Reduced Configuration Overhead ဒီတစ္ခ်က္ဟာ branch offices ေပါင္းမ်ားစြာကို secure VPN ခ်ိတ္ဆက္ဖို႔ တာ၀န္ယူရတဲ့ Network Enginner ေတြအတြက္ အေတာ္သက္သာသြားေစမယ့္ အခ်က္ပဲျဖစ္ပါတယ္။ အကယ္၍သာ branch office ေပါင္း (1000) ရွိတဲ႔ network တစ္ခုအတြက္ point to point vpn topology ကိုပဲ အသံုးျပဳခဲ့မယ္ဆိုရင္ P2P vpn tunnel ေပါင္း 1000 တည္ေဆာက္ရမွာျဖစ္ပါတယ္။ ဒီအခါမွာ ipsec နဲ႔ ပတ္သက္တဲ႔ configuration ေတြဟာ P2P tunnel တစ္ခုျခင္းစီမွာ ထည့္