<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Source interface based routing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/source-interface-based-routing/m-p/4851345#M1101367</link>
    <description>&lt;P&gt;Pretty sure this isn't possible, but worth an ask.&lt;/P&gt;&lt;P&gt;I'd like to policy route some of our traffic based on application awareness. This is all being done by a Sophos XG and then routed via an alternate link to an ASA which is one of our internet /AnyConnect gateways.&lt;/P&gt;&lt;P&gt;As the ASA already has static routes inside for addresses any traffic the Sophos XG policy routes to the ASA is sent back via it's inside interface causing asymmetric routing.&lt;/P&gt;&lt;P&gt;I can fix this by NAT'ing outbound traffic that's been policy routed on the XG, however I can only do the NAT based on source/destination IP, not application awareness&lt;/P&gt;&lt;P&gt;Other than re-architecting the network, can I policy route traffic on the ASA so if the traffic was originally sourced from a specific interface then return traffic would be routed via this interface?&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2023 11:54:26 GMT</pubDate>
    <dc:creator>richyvrlimited</dc:creator>
    <dc:date>2023-06-08T11:54:26Z</dc:date>
    <item>
      <title>Source interface based routing</title>
      <link>https://community.cisco.com/t5/network-security/source-interface-based-routing/m-p/4851345#M1101367</link>
      <description>&lt;P&gt;Pretty sure this isn't possible, but worth an ask.&lt;/P&gt;&lt;P&gt;I'd like to policy route some of our traffic based on application awareness. This is all being done by a Sophos XG and then routed via an alternate link to an ASA which is one of our internet /AnyConnect gateways.&lt;/P&gt;&lt;P&gt;As the ASA already has static routes inside for addresses any traffic the Sophos XG policy routes to the ASA is sent back via it's inside interface causing asymmetric routing.&lt;/P&gt;&lt;P&gt;I can fix this by NAT'ing outbound traffic that's been policy routed on the XG, however I can only do the NAT based on source/destination IP, not application awareness&lt;/P&gt;&lt;P&gt;Other than re-architecting the network, can I policy route traffic on the ASA so if the traffic was originally sourced from a specific interface then return traffic would be routed via this interface?&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 11:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-interface-based-routing/m-p/4851345#M1101367</guid>
      <dc:creator>richyvrlimited</dc:creator>
      <dc:date>2023-06-08T11:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: Source interface based routing</title>
      <link>https://community.cisco.com/t5/network-security/source-interface-based-routing/m-p/4851366#M1101371</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Policy based routing is supported on ASA from version 9.4.1.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.networkstraining.com/cisco-asa-policy-based-routing-pbr/" target="_blank"&gt;https://www.networkstraining.com/cisco-asa-policy-based-routing-pbr/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 12:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-interface-based-routing/m-p/4851366#M1101371</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-06-08T12:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Source interface based routing</title>
      <link>https://community.cisco.com/t5/network-security/source-interface-based-routing/m-p/4851381#M1101373</link>
      <description>&lt;P&gt;Not really what I asked. I know I can policy route based on source address. What I want to do is policy route based on the original source &lt;EM&gt;interface&lt;/EM&gt; of the connection.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 13:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-interface-based-routing/m-p/4851381#M1101373</guid>
      <dc:creator>richyvrlimited</dc:creator>
      <dc:date>2023-06-08T13:20:38Z</dc:date>
    </item>
  </channel>
</rss>

