Cisco ASA with sonic wall content filter

apollo_sj

Distinguished
Feb 16, 2011
8
0
18,510
Hey Guys. I'm really in need of the suggestions.
Our location has around 200 users and we need to force in some content filtering in the internet access ASAP.

Our current setup is
---outside--- cisco ASA --- inside


Currently ASA is really doing great job. Its handling out DHCP request also.

Instead of ASA content filtering license, we bought SONIC WALL TZ 300 to enable content filtering service(CFS).
and want to connect it to ASA.

Since ASA is doing its job in a great way we want to keep ASA for firewall only and other jobs like dhcp and mainly CFS in sonic wall.
so proposed setup looks like this
---outside--cisco ASA (firewall)---Sonic wall(routing, dhcp,CFS)--inside--

Question to myself was how to forward traffic from ASA to sonicwall?? Should i use any encapsulation between them ?? Which port should i use in Sonicwall to connect to ASA-- LAN or WAN??

Please guide how to implement this technically.

Any other setup suggestion is most welcome.

 
Solution
The ASA would only provide DHCP to the Sonicwall in the config you proposed. The Sonic wall would provide DHCP to the internal networked devices.

Honestly, you really only need one device. Also, make sure the 2 devices use different internal address space (i.e. ASA: 192.168.0.X and Sonicwall 192.168.1.X).

apollo_sj

Distinguished
Feb 16, 2011
8
0
18,510



yeah. we can. But we want to retain ASA since it's doing great job and is used for IPsec link with other cisco ASA in offshore location. Also, ASA got 3GB RAM and Sonic has only 1GB.. So we don't wanna burden Sonic with all the things and that's the reason we wanna utilize both.
 

COLGeek

Cybernaut
Moderator
Understood. You should just be able to connect the ASA to the Sonicwall as proposed. Securing the link seems excessive as the ASA is protecting the network now. Used fixed IPs between the ASA and the Sonicwall. Seems fairly straight-forward.

Have you tried this new config yet?
 

apollo_sj

Distinguished
Feb 16, 2011
8
0
18,510
COLGeek... Thx for the instant reply.
No, i haven't tried the config yet. Still in planning stage.

Okay.So no need of any secure link between them. Cool!! Now, since i want ASA to do the NATing where do i connect ASA in Sonic wall?? LAN or WAN port??
 

apollo_sj

Distinguished
Feb 16, 2011
8
0
18,510
okay. Thx a lot!!
What if i want ASA to retain its DHCP job. Then which port should i use in Sonic wall to connect to ASA??

BTW is it good to keep Sonic in Inside network???
 

COLGeek

Cybernaut
Moderator
The ASA would only provide DHCP to the Sonicwall in the config you proposed. The Sonic wall would provide DHCP to the internal networked devices.

Honestly, you really only need one device. Also, make sure the 2 devices use different internal address space (i.e. ASA: 192.168.0.X and Sonicwall 192.168.1.X).
 
Solution