<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Dinesh. I will try in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043862#M134409</link>
    <description>&lt;P&gt;Thanks Dinesh. I will try your suggestion. I was under impression that there is a&amp;nbsp;&lt;SPAN&gt;an&amp;nbsp;&lt;/SPAN&gt;&lt;B&gt;implicit deny&lt;/B&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;at the end of&amp;nbsp;route-map acl. Do you know if SLA monitor requires a security plus license? I enabled the SLA monitor but the debugging not showing&amp;nbsp;anything?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2017 02:45:07 GMT</pubDate>
    <dc:creator>ms-tech-001</dc:creator>
    <dc:date>2017-07-05T02:45:07Z</dc:date>
    <item>
      <title>Permanent route on Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043858#M134405</link>
      <description>&lt;P&gt;Can I please know if there is anyway to make a permanent static route on cisco asa 5506x? &amp;nbsp;I am basically looking for a PPTPoE route to be available &amp;nbsp;in the routing table&amp;nbsp;all the time so that my backup route won't get activated when there is some issue with the primary connection.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;MS&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043858#M134405</guid>
      <dc:creator>ms-tech-001</dc:creator>
      <dc:date>2019-03-12T09:39:02Z</dc:date>
    </item>
    <item>
      <title>You can use metric to define</title>
      <link>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043859#M134406</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can use metric to define the route to be chosen but once this is down, the other route (with higher metric) will take over.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Is there any specific reason you want to keep the backup route but not have it activated once the primary goes &lt;G class="gr_ gr_15 gr-alert gr_gramm gr_inline_cards gr_run_anim Style multiReplace" id="15" data-gr-id="15"&gt;down ?&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;I'd suggest you have IP SLA setup to monitor ISP links&lt;BR /&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118962-configure-asa-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118962-configure-asa-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2017 06:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043859#M134406</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2017-07-03T06:41:05Z</dc:date>
    </item>
    <item>
      <title>Thanks for the reply Dinesh.</title>
      <link>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043860#M134407</link>
      <description>&lt;P&gt;Thanks for the reply Dinesh. We have two ISP connected to our asa, one for general internet stuff and the second one dedicated to&amp;nbsp;voip. We are using route-map to send the voip traffic to the backup connection. We thought about SLA monitoring but we have only base license. I believe that you need a security plus license to enable SLA? Also we noticed some issue with route-map when the backup connection&amp;nbsp;become active and I think this issue will continue &amp;nbsp;even we proceed with SLA monitor. Our route-map acl has configured to permit only the&amp;nbsp;&amp;nbsp;voip gateway to use the backup connection and this works fine when both connections are active but as soon as the primary route disappeared from the routing table all other devices will start to use the backup connection. Can I please know why this is happening and is there anyway to stop this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;MS&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2017 07:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043860#M134407</guid>
      <dc:creator>ms-tech-001</dc:creator>
      <dc:date>2017-07-03T07:09:59Z</dc:date>
    </item>
    <item>
      <title>One thing that you can try is</title>
      <link>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043861#M134408</link>
      <description>&lt;P&gt;One thing that you can try is to modify the access-list applied to PBR on 2nd ISP which is dedicated to &lt;G class="gr_ gr_170 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="170" data-gr-id="170"&gt;voip&lt;/G&gt; gateway so that the data traffic is implicitly dropped due to &lt;G class="gr_ gr_245 gr-alert gr_gramm gr_inline_cards gr_run_anim Grammar multiReplace" id="245" data-gr-id="245"&gt;deny&lt;/G&gt; in access-list.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2017 07:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043861#M134408</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2017-07-03T07:38:25Z</dc:date>
    </item>
    <item>
      <title>Thanks Dinesh. I will try</title>
      <link>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043862#M134409</link>
      <description>&lt;P&gt;Thanks Dinesh. I will try your suggestion. I was under impression that there is a&amp;nbsp;&lt;SPAN&gt;an&amp;nbsp;&lt;/SPAN&gt;&lt;B&gt;implicit deny&lt;/B&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;at the end of&amp;nbsp;route-map acl. Do you know if SLA monitor requires a security plus license? I enabled the SLA monitor but the debugging not showing&amp;nbsp;anything?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 02:45:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043862#M134409</guid>
      <dc:creator>ms-tech-001</dc:creator>
      <dc:date>2017-07-05T02:45:07Z</dc:date>
    </item>
    <item>
      <title>The IP SLA Monitoring could</title>
      <link>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043863#M134410</link>
      <description>&lt;P&gt;The IP SLA Monitoring could be configured in all type of licenses, there are no specific requirements for this feature.&lt;BR /&gt;&lt;BR /&gt;I doubt this is possible via PBR. Selective traffic propagation might not work as track will failover all the traffic. You might want to create an access-list entry for an access-list applied on ingress interface that will block your traffic which should not be allowed via &lt;G class="gr_ gr_242 gr-alert gr_gramm gr_inline_cards gr_run_anim Grammar only-ins replaceWithoutSep" id="242" data-gr-id="242"&gt;second&lt;/G&gt; ISP.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 04:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/permanent-route-on-cisco-asa/m-p/3043863#M134410</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2017-07-05T04:45:20Z</dc:date>
    </item>
  </channel>
</rss>

