<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Load-sharing for Cisco ASA. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/load-sharing-for-cisco-asa/m-p/3501311#M134449</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply Jason. This is actually the first time that I've heard of this Traffic Zones. May need to lab this up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Jun 2017 09:32:47 GMT</pubDate>
    <dc:creator>santiago.jem</dc:creator>
    <dc:date>2017-06-30T09:32:47Z</dc:date>
    <item>
      <title>Load-sharing for Cisco ASA.</title>
      <link>https://community.cisco.com/t5/network-security/load-sharing-for-cisco-asa/m-p/3501309#M134447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello experts, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good day! &lt;/P&gt;&lt;P&gt;I have this device, Cisco ASA 5515 with version ASA 9.5(2)2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we do a load-sharing on our internet bound traffic with 2 internet circuit coming from 2 different ISP?&lt;/P&gt;&lt;P&gt;What we plan to do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Users on VLAN10 will route through ISP1 - if ISP1 goes down, traffic will route to ISP2.&lt;/P&gt;&lt;P&gt;2. Users on VLAN 20 will route through ISP2 - if ISP2 goes down, traffic will route to ISP1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that VLAN10 to be routed to ISP1 and VLAN20 to be routed to ISP2 can be done through route-maps with 2 sequence numbers.&lt;/P&gt;&lt;P&gt;It is when the links fails and moves traffic to the other link where things get a bit complicated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this even possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jun 2017 11:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/load-sharing-for-cisco-asa/m-p/3501309#M134447</guid>
      <dc:creator>santiago.jem</dc:creator>
      <dc:date>2017-06-29T11:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Load-sharing for Cisco ASA.</title>
      <link>https://community.cisco.com/t5/network-security/load-sharing-for-cisco-asa/m-p/3501310#M134448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd probably just use load sharing using zones and ignore the vlans unless there is a business reason to do so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/general/asa-general-cli/interface-zones.html#pgfId-1068427" style="font-size: 10pt;" title="http://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/general/asa-general-cli/interface-zones.html#pgfId-1068427"&gt;CLI Book 1: Cisco ASA Series General Operations CLI Configuration Guide, 9.3 - Traffic Zones [Cisco ASA 5500-X Series Fi…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But what you want to do is possible.&amp;nbsp; Check the 'verify availability' portion of this link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/general/asa-94-general-config/route-policy-based.pdf" style="font-size: 10pt;" title="http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/general/asa-94-general-config/route-policy-based.pdf"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/general/asa-94-general-config/route-policy-bas…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the doc:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify if the next IPv4 hops of a route map are available:&lt;/P&gt;&lt;P&gt;set ip next-hop verify-availability next-hop-address sequence_number track object&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure an SLA monitor tracking object to verify the reachability of the next-hop. To verify the availability of multiple next-hops, multiple set ip next-hop verify-availability commands can be configured with different sequence numbers and different tracking objects.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jun 2017 14:00:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/load-sharing-for-cisco-asa/m-p/3501310#M134448</guid>
      <dc:creator>Jason Gervia</dc:creator>
      <dc:date>2017-06-29T14:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Load-sharing for Cisco ASA.</title>
      <link>https://community.cisco.com/t5/network-security/load-sharing-for-cisco-asa/m-p/3501311#M134449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply Jason. This is actually the first time that I've heard of this Traffic Zones. May need to lab this up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jun 2017 09:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/load-sharing-for-cisco-asa/m-p/3501311#M134449</guid>
      <dc:creator>santiago.jem</dc:creator>
      <dc:date>2017-06-30T09:32:47Z</dc:date>
    </item>
  </channel>
</rss>

