<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030455#M145953</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're right you can't upgrade to latest version supporting pbr and what you want to achieve its pbr.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no way to achieve a source routing. You can do workaround to quite load balance the traffic between both ISPs.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2017 02:03:28 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2017-03-09T02:03:28Z</dc:date>
    <item>
      <title>outbound routing with two ISP links</title>
      <link>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030454#M145952</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have two ISP outbound circuits connected to a 5520&amp;nbsp; ASA version 8.4(7).&amp;nbsp;&amp;nbsp; I can't figure out how to create a route based on source ip rather than destination IP.&amp;nbsp;&amp;nbsp; In a nutshell, I want to route WIFI and web conferencing via one interface and web servers via the other interface to split the traffic load.&amp;nbsp;&amp;nbsp; I can't do regular load balancing because were not an Autonomous System and the ISPs are different.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The logic needs to work something like this:&lt;/P&gt;
&lt;P&gt;Source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gateway&lt;/P&gt;
&lt;P&gt;Vlan100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPaddress for ISP1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;--------- Send Wifi trafic to ISP1&lt;/P&gt;
&lt;P&gt;Vlan200&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPaddress for ISP1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;------------send web conference traffic to ISP1&lt;/P&gt;
&lt;P&gt;0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPaddress for ISP2&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;---------&amp;nbsp; default gateway via ISP2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This looks like policy based routing to me, but I don't think I can upgrade the version on my ASA to 9.4.&amp;nbsp;&amp;nbsp; Is there I work around I could use?&amp;nbsp;&amp;nbsp; I'm trying to figure out how to do it with ACL's, but I'm coming up short on ideas.&amp;nbsp;&amp;nbsp; The only idea I have would be to connect a second firewall and switch to my Core switch and manage that traffic as if it was a remote office with a layer2 point to point connection.&amp;nbsp;&amp;nbsp; I'd rather not add the extra cost and complexity to the setup, if I can avoid it.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:59:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030454#M145952</guid>
      <dc:creator>andrewgori</dc:creator>
      <dc:date>2019-03-26T00:59:48Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030455#M145953</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're right you can't upgrade to latest version supporting pbr and what you want to achieve its pbr.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no way to achieve a source routing. You can do workaround to quite load balance the traffic between both ISPs.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 02:03:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030455#M145953</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-03-09T02:03:28Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030456#M145954</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please check the below link having scenarios of PBR supported on ASA if this meets your requirement.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/general/asa-94-general-config/route-policy-based.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Tripat Kaur&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 18:28:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030456#M145954</guid>
      <dc:creator>trdatta</dc:creator>
      <dc:date>2017-03-09T18:28:47Z</dc:date>
    </item>
    <item>
      <title>Is it possible to load</title>
      <link>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030457#M145955</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it possible to load balance outbound traffic even when it is natted?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 21:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030457#M145955</guid>
      <dc:creator>andrewgori</dc:creator>
      <dc:date>2017-03-09T21:48:21Z</dc:date>
    </item>
    <item>
      <title>Looking at that, I think PBR</title>
      <link>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030458#M145956</link>
      <description>&lt;P&gt;Looking at that, I think PBR would work using an ACL and policy specifying the next hop based on source address.&amp;nbsp; The trouble is my ASA is a 5520 and will only run version 9.1x&lt;/P&gt;
&lt;P&gt;Right now I need to work out a way to make this happen with the hardware we have on hand.&amp;nbsp;&amp;nbsp; I have a spare 5515 ASA and a 2960 switch that I could put into play.&amp;nbsp;&amp;nbsp; Right now I'm thinking of a scheme that would work like this:&lt;/P&gt;
&lt;P&gt;1) trunk VLAN100 and VLAN200 from the core switch to a second ASA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Connect second ASA to ISP1&lt;/P&gt;
&lt;P&gt;3) Address the vlan interfaces on the second ASA and use those as the GW address for each VLAN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4) set default route on second ASA to use ISP1&lt;/P&gt;
&lt;P&gt;5) create static routes on the new ASA for all internal networks that would point to my core switch.&amp;nbsp; This entail creating a couple dozen static routes.&lt;/P&gt;
&lt;P&gt;6) create static routes on my core switch pointing to the new ASA for VLAN100 and VLAN200.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Do you think this would work?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 22:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030458#M145956</guid>
      <dc:creator>andrewgori</dc:creator>
      <dc:date>2017-03-09T22:25:32Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030459#M145957</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes it should work. From your core switch, you can also use pbr to route to 1st asa or 2nd asa.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 02:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030459#M145957</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-03-10T02:14:44Z</dc:date>
    </item>
    <item>
      <title>You can load balance based on</title>
      <link>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030460#M145959</link>
      <description>&lt;P&gt;You can load balance based on ports, for example http and https to 1 isp and the rest to other isp.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or you can set 2 routes for example 128.0.0.0/1 to 1 isp and 0.0.0.0/1 to the other isp.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Does that answer your question&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 02:19:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outbound-routing-with-two-isp-links/m-p/3030460#M145959</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-03-10T02:19:18Z</dc:date>
    </item>
  </channel>
</rss>

