Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Two security contexts, one outside network

Status
Not open for further replies.

fredmaine

MIS
Mar 12, 2009
38
US
I'd like to start a conversation here with some that is using multiple security contexts, sharing the same outside interface.

This is discussion started here elsewhere but I wanted to get it out under the right subject.

I'm considering using multiple security contexts as a solution to a problem.

In a nutshell, I want any inbound SMTP to be forwarded to an internal SMTP server A, except inbound SMTP from a -specific- network, which I want forwarded to a second internal SMTP server B.

My idea to solve this with multiple contexts would be:

Security context A:
Access List:
1. Deny SMTP packets from Specific_Network
2. Permit SMTP packets from anywhere else
3. all other non-SMTP access rules go here
NAT:
1. Route all SMTP packets to server A
2. other non-SMTP NAT rules go here

Security context B:
Access List:
1. Permit SMTP packets from Specific_Network
2. Deny SMTP packets from anywhere else
NAT:
1. Route all SMTP packets to server B

Both contexts share the same interface and the same outside network, but have unique MAC addresses, which can be done on the ASA 5510 according to David Huckaby/Cisco Press.

I'm making a broad assumption here, and that is that both contexts see all of the same packets arriving on the interface that they share.

In other words, for our email problem, both contexts get the same SMTP packets but each deals with one condition or other, in an un-ambiguous way. One context denies what the other context permits.

Does anyone know if this is feasable, or if there is another more direct solution?
 
Multiple context mode may work, but you're going to lose some functionality such as VPN, dynamic routing, and multicast support, but if you're ok with it give it a shot.

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Ah, VPN. Nope, gotta keep that.

Still, as a learning topic here in case it's useful to others, I still wouldn't mind a discussion with someone that actually runs multiple contexts now. I'm beginning to think that's a rare case, let alone running multiple contexts with one outside network.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top