Correct setup?



  • Setup:
    One WAN connection
    Several VLANs though are routed via HP Core Switch (5406zl)
    Cisco 2911 – Route to a policy enforcer

    WAN (block of 5 IP's) --> PF SENSE (EXTERNAL) --> PFSENSE (INTERNAL: 172.18.200.9) --> CISCO 2911 (IP: 172.18.200.10) --> HP LAYER 3 CORE SWITCH (VLAN ROUTING).

    The Cisco 2911 is used for a policy enforcer since the HP Layer 3 core switch isn't granular enough with route maps and flow data.  On the PFSense box I have a route for the internal (EX: 192.168.0.0/16) back to my Cisco 2911 (172.18.200.10).  I was able to get traffic to flow though and back to my network, however I want to know if this is the correct setup or if there is something else I should be doing?  The PFSense box will be doing NAT.  Though I am able to see my internal network IPs going through the PFSense instead of the 172.18.200.10 address via the Cisco.

    My other question would be can the PFSense box do route maps like the Cisco 2911?


Log in to reply