This probably sounds a little crazy, but I'm wondering if there is a way to setup a Cisco router with two ethernet interfaces, to work as a switch, instead of as a router?
Here's what I'm trying to accomplish...
Our company has a wireless ISP (Airband Communications). They have a dish on our roof that connects via a CAT5 ethernet cable to our Watchguard firewall. The firewall is doing NAT. So there is no router involved in our setup.
I need to start analyzing traffic leaving/entering our network, and monitoring what users are doing on the internet. There is a great free tool for doing this, which uses Netflow outputs from your router. Problem is that we aren't using a router, and the Watchguard firewall doesn't have the ability to spit out Netflow data.
So I'm wondering if there is a way to put a Cisco router between the dish and my firewall, but give both ethernet interfaces public IP's from my block, and then have the firewall still do NAT...which effectively means the router would be acting as a switch, that can export Netflow data.
Can anybody tell me how to do this, or if you have any other suggestions about how to accomplish my goal?
FYI...replacing the Watchguard firewall with a Cisco box isn't an option...unfortunately it won't be that easy.
Thanks!
Here's what I'm trying to accomplish...
Our company has a wireless ISP (Airband Communications). They have a dish on our roof that connects via a CAT5 ethernet cable to our Watchguard firewall. The firewall is doing NAT. So there is no router involved in our setup.
I need to start analyzing traffic leaving/entering our network, and monitoring what users are doing on the internet. There is a great free tool for doing this, which uses Netflow outputs from your router. Problem is that we aren't using a router, and the Watchguard firewall doesn't have the ability to spit out Netflow data.
So I'm wondering if there is a way to put a Cisco router between the dish and my firewall, but give both ethernet interfaces public IP's from my block, and then have the firewall still do NAT...which effectively means the router would be acting as a switch, that can export Netflow data.
Can anybody tell me how to do this, or if you have any other suggestions about how to accomplish my goal?
FYI...replacing the Watchguard firewall with a Cisco box isn't an option...unfortunately it won't be that easy.
Thanks!