- Community Home
- >
- Networking
- >
- Switching and Routing
- >
- HPE Aruba Networking & ProVision-based
- >
- Re: MGMT VLAN /Assymetry Routing questions
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-26-2021 04:13 AM
03-26-2021 04:13 AM
MGMT VLAN /Assymetry Routing questions
Hi,
it's my first post here, english is not my native language and my knowledge in network is average so please bear with me.
To best resume my issue, i ll paste a link of a post i found about similar issue wich was fixed by using VRF which is not possible with the aruba switch i am using.
https://ltlnetworker.files.wordpress.com/2015/08/m13-asymm-external.png?w=660&h=643
I have managment network 10.14.0.x, with my servers on, and layer3 core switch (2930F) with routing on.
There is a transit VLAN between my firewall and my core switch. and management interface of my firewall is connected to an untagged management VLAN port of the core switch.
i would like to be able when i connect from VPN to my firewall, to access to managment vlan and other vlans.
the problem is that it creates and assymetry, the core switch default route being the firewall transit interface.
What would be the best practice to do such thing?
I gues i could just remove the management link btween firewall and core, and route everything through the transit VLAN, but isnt it bettr to have dedicated management interface?
Thanks in advance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-23-2021 09:47 AM
04-23-2021 09:47 AM
Re: MGMT VLAN /Assymetry Routing questions
Hello,
Is it possible for you to share the detailed network diagram?
Thanks!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-27-2021 01:16 PM
04-27-2021 01:16 PM
Re: MGMT VLAN /Assymetry Routing questions
Hi @boombasstic I don't see any routing asymmetry: I mean...I don't see it necessarily...the OoBM interface of your Firewall is indeed truly OoB (isn't it?) and it should admit an IP, a Subnet Mask and a Default Gateway...so, de-facto, it's like having an host connected (as it is exactly in your scenario) to your internal infrastructure: Firewall's OoBM interface should be then treated as any other host LAN interface...it should use the SVI on your Aruba 2930F Core Switch (IP Routing enabled) as its default gateway and thus to reach any other (permitted) outside network as any other host of your internal network (considering the same network segment) it will use your routing Aruba 2930F which then will use its Transit VLAN to route traffic for any other non locally connected network (0/0 via Transit IP on Firewall LAN interface).
I don't see any asymmetry...neither for outgoing traffic route (Core Switch directly connected Internal network(s) -> Core Switch Transit VLAN -> Firewall LAN -> NAT -> Firewall WAN -> VPN Tunnel thorugh Internet -> VPN Client) nor for incoming one (Internet VPN Client -> VPN Tunnel through Internet -> Firewall WAN -> NAT -> Firewall LAN -> Core Switch Transit VLAN -> Core Switch directly connected Internal network(s)).
Am I wrong and there are potentially lacking details in your description to invalidate my thoughts?
I'm not an HPE Employee
