<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You need to define the remote in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025154#M146861</link>
    <description>&lt;P&gt;You need to define the remote network not the network connected to the ASA interface. &amp;nbsp;To be more specific, the network at the remote side of the site to site VPN tunnel.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Sat, 04 Feb 2017 22:57:05 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2017-02-04T22:57:05Z</dc:date>
    <item>
      <title>multiple default route in ASA</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025149#M146843</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;How ca i define multiple default route in ASA?&lt;/P&gt;
&lt;P&gt;route tcvpn 0 0 10.240.20.1&lt;/P&gt;
&lt;P&gt;route cacvpn 0 0 10.240.30.1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;whaen i put the second route i get this route is aleready exisit. what is the solution?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:53:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025149#M146843</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2019-03-12T08:53:13Z</dc:date>
    </item>
    <item>
      <title>You can do this if you</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025150#M146845</link>
      <description>&lt;P&gt;You can do this if you configure both interfaces as a part of a traffic zone and use ecmp.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/general/asa-general-cli/interface-zones.html#56513&lt;/P&gt;
&lt;P&gt;You would have to run Asa version 9.3 and above&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 13:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025150#M146845</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-02-04T13:43:44Z</dc:date>
    </item>
    <item>
      <title>I'm not sure what you really</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025151#M146849</link>
      <description>&lt;P&gt;I'm not sure what you really want to achieve, but it's&amp;nbsp;very&amp;nbsp;likely that&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/general/asa-94-general-config/route-policy-based.html"&gt;PBR is the solution&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 16:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025151#M146849</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-02-04T16:36:37Z</dc:date>
    </item>
    <item>
      <title>Check your other post.  You</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025152#M146853</link>
      <description>&lt;P&gt;Check your other post. &amp;nbsp;You need to setup static routes for the remote VPN subnets. &amp;nbsp;If there are many remote subnets I suggest summarizing them.&lt;/P&gt;
&lt;P&gt;Although, zoned ECMP would allow you to setup default routes pointing out each interface, the problem you will run into is that traffic will be load-balanced across these interfaces, meaning traffic that is destined for VPN1 might be sent out the wrong interface.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 20:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025152#M146853</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-02-04T20:47:44Z</dc:date>
    </item>
    <item>
      <title>thanks Marius but when i</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025153#M146857</link>
      <description>&lt;P&gt;thanks Marius but when i setup static routes for the subnet i get "error this interface is directly connected"&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 22:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025153#M146857</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-04T22:50:05Z</dc:date>
    </item>
    <item>
      <title>You need to define the remote</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025154#M146861</link>
      <description>&lt;P&gt;You need to define the remote network not the network connected to the ASA interface. &amp;nbsp;To be more specific, the network at the remote side of the site to site VPN tunnel.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 22:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025154#M146861</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-02-04T22:57:05Z</dc:date>
    </item>
    <item>
      <title>thanks Marius i understand</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025155#M146865</link>
      <description>&lt;P&gt;thanks Marius i understand what you say . so i think i will put&amp;nbsp;&lt;SPAN&gt; zoned ECMP because i don't have the address ip for site to site VPN i should contact the provider&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 23:15:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025155#M146865</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-04T23:15:04Z</dc:date>
    </item>
    <item>
      <title>As mentioned earlier zoned</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025156#M146869</link>
      <description>&lt;P&gt;As mentioned earlier zoned ECMP will not solve your issue as this will just load-balance the traffic over the interfaces. &amp;nbsp;That means that traffic for one VPN site could be sent out the wrong interface. &amp;nbsp;to solve your problem you MUST get the remote site adresses and enter static routes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But is the site to site VPN terminated on the ASA or the ISP router?&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 23:20:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025156#M146869</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-02-04T23:20:20Z</dc:date>
    </item>
    <item>
      <title>the site to site VPN</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025157#M146872</link>
      <description>&lt;P&gt;the site to site VPN terminated on the ISP router&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 23:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025157#M146872</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-04T23:23:13Z</dc:date>
    </item>
    <item>
      <title>thanks Rahul for ur helps, </title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025158#M146874</link>
      <description>&lt;P&gt;thanks Rahul for ur helps,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i should put this 2 route in my asa:&lt;/P&gt;
&lt;P&gt;route tcvpn 10.240.1.0 255.255.255.0 10.240.20.1&lt;/P&gt;
&lt;P&gt;route cacvpn 10.240.1.0 255.255.255.0 10.240.30.1&lt;/P&gt;
&lt;P&gt;but when put the second route i get error this route already exist, what should i do?&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;MM&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 22:08:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025158#M146874</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-09T22:08:06Z</dc:date>
    </item>
    <item>
      <title>What is the ASA version you</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025159#M146876</link>
      <description>&lt;P&gt;What is the ASA version you have? And are the 2 interfaces part of the same zone? Refer to the article to understand zoned ECMP:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/general/asa-general-cli/interface-zones.html#56513&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 03:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025159#M146876</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-02-10T03:54:52Z</dc:date>
    </item>
    <item>
      <title>i have version 9.2, the 2</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025160#M146877</link>
      <description>&lt;P&gt;i have version 9.2, the 2 interfaces part of different zone my architecture is like that:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/asa-arch.png" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 09:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025160#M146877</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-10T09:17:56Z</dc:date>
    </item>
    <item>
      <title>Is this two sites with the</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025161#M146878</link>
      <description>&lt;P&gt;Is this two sites with the same subnet (10.240.1.0/24)? or is it two paths to the same site?&lt;/P&gt;
&lt;P&gt;If this is to two different sites then we need to do some NATing on the ASA (or the remote end for that matter). &amp;nbsp;But first lets establish if these are two seperate sites or two paths to the same site.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please remember to select a correct answer and rate helpful posts&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 09:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025161#M146878</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-02-10T09:39:29Z</dc:date>
    </item>
    <item>
      <title>there are two seperate site,</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025162#M146879</link>
      <description>&lt;P&gt;there are two seperate site, what is the NATing i should do ?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 09:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025162#M146879</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-10T09:47:38Z</dc:date>
    </item>
    <item>
      <title>You need to identify what the</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025163#M146880</link>
      <description>&lt;P&gt;You need to identify what the traffic needs are. &amp;nbsp;Are the remote sites only going to access resources at the main site behind the ASA or will the main site also need to access services at the remote sites?&lt;/P&gt;
&lt;P&gt;Depending on the answer to the question above, you will either need to dynamic NAT to one of the site (if just the remote site needs access to main site). &amp;nbsp;If the main site needs access to some resources at the remote site, then you will need to create static one to one NAT for those resources and all other traffic can use a dynamic NAT.&lt;/P&gt;
&lt;P&gt;You only need to NAT one of the sites IPs. the second site can use its original IP.&lt;/P&gt;
&lt;P&gt;Are these site to site VPNs?&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please remember to select a correct answer and rate helpful posts&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 10:07:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025163#M146880</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-02-10T10:07:34Z</dc:date>
    </item>
    <item>
      <title>in my case the main site only</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025164#M146881</link>
      <description>&lt;P&gt;in my case&amp;nbsp;&lt;SPAN&gt;the main site only need to access services at the remote sites&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(VPN is between two ISP router)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 10:16:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025164#M146881</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-10T10:16:21Z</dc:date>
    </item>
    <item>
      <title>if they are two paths to the</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025165#M146882</link>
      <description>&lt;P&gt;if they are two paths to the same site the solution is ECMP? that's right?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 12:02:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025165#M146882</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-10T12:02:54Z</dc:date>
    </item>
    <item>
      <title>if the path is to the same</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025166#M146883</link>
      <description>&lt;P&gt;if the path is to the same site or to the internet then zoned ECMP is the solution.&lt;/P&gt;
&lt;P&gt;Now since the main site needs to access services at the remote site you will need to statically NAT those services at one of the sites. then you would access the services at that one site by using the NATed IP.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please remember to select a correct answer and rate helpful posts&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 12:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025166#M146883</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-02-10T12:08:59Z</dc:date>
    </item>
    <item>
      <title>the ECMP Zoned is not</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025167#M146884</link>
      <description>&lt;P&gt;the ECMP Zoned is not supported in my ASA 9.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;what the nat i should put in my case?&lt;/P&gt;
&lt;P&gt;this is my architecture:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/asa-arch_1.png" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 15:10:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025167#M146884</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-10T15:10:58Z</dc:date>
    </item>
    <item>
      <title>thanks Karsten but how can i</title>
      <link>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025168#M146885</link>
      <description>&lt;P&gt;thanks Karsten but how can i define it in my ASA version 9.2?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 18:41:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-default-route-in-asa/m-p/3025168#M146885</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2017-02-10T18:41:13Z</dc:date>
    </item>
  </channel>
</rss>

