OSPF question

Started by Nerm, March 22, 2016, 07:48:38 AM

Previous topic - Next topic

Nerm

Quote from: dlots on March 23, 2016, 07:20:53 AM
How would BGP work?

yes router 1 and 2 will exchange routes, but if you don't have a tunnel of some kind (which as ristau5741 your FW should be able to see into as long as your not encrypting it) the FW won't know what to do with the traffic once R1 sends it up there to go to R2.

You can't make it a transparent (L2) firewall can you?

Utilizing multihop....I did a lab today using bgp multihop for this proposed idea and it worked. *Let the flaming begin* :)

An unencrypted tunnel was my next option when told it "must" go through the firewall but I am also being told that the Meraki can't see tunneled traffic even if unencrypted. Admittedly I am very new to Meraki so I have no knowledge as to whether this is true or not. I should probably research that to see if all of my "provided" information is correct.

Quote from: LynK on March 23, 2016, 07:51:11 AM
If you have any sort of outside switch, on the other end of the firewall, I do not see what the problem is here? Connect them via L2, and do not have them go through a FW.

This is actually what I wanted to do in the first place but the "boss" demands this traffic go through the firewall.

dlots

Still confused, I know you can peer across it with multi-hop but I am still confused how this fixes anything, when R1 sends the FW a packet that is being forwarded by the routes learned by BGP (lets say 1.1.1.1) R1 and R2 both now how to get to 1.1.1.1 via BGP, but how does the FW know what to do with the packet, the only routes it knows are the ones directly connected, or am I missing something?

Nerm

Quote from: dlots on March 23, 2016, 03:58:50 PM
Still confused, I know you can peer across it with multi-hop but I am still confused how this fixes anything, when R1 sends the FW a packet that is being forwarded by the routes learned by BGP (lets say 1.1.1.1) R1 and R2 both now how to get to 1.1.1.1 via BGP, but how does the FW know what to do with the packet, the only routes it knows are the ones directly connected, or am I missing something?

Static routes on the FW.