<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic So, this is my understamding in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063543#M147245</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;So, this is my understamding of your setup, please correct me if I am wrong somewhere:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ISP1 - default gateway with preferred route towards internet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;ISP2 - default gateway with less preferred route towards internet&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In this case, inbound traffic should work for both ISP since reply traffic will follow the same path back as it came in.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Now, as per your scenario, lets say ISP1 fails and ISP2 is handling incoming traffic for both mx records . Now, when the ISP1 comes back up, if the inbound traffic arrives on ISP1, it will work. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;It all depends on how quikcly ISP1 can punt the traffic for ISP1 towards ISP1. ASA will have a limited role to play in there since its a recipient. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Depends on ISP what criteria they have to identify of when the ISP1 is active or down. Looks like a routing question that should be pointed to the ISP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Let me know if I missed out on something or there is some additional questions.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2017 20:39:17 GMT</pubDate>
    <dc:creator>Ajay Saini</dc:creator>
    <dc:date>2017-01-27T20:39:17Z</dc:date>
    <item>
      <title>E-Mail Server on Asa</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063538#M147239</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;My need is for our mailserver is below:&lt;/P&gt;
&lt;P&gt;Able to send and receive emails from - to outside internet domains with two public ip addresses from&lt;/P&gt;
&lt;P&gt;ISP1 and ISP2. Our Dns records for ourdomain.com are on the ISP1 and ISP2's Name Servers with the same value of MX records 10.&lt;/P&gt;
&lt;P&gt;Scenario :&lt;/P&gt;
&lt;P&gt;If the link of ISP1 fails email relaying and sending for ourdomain.com will be able to continue from the ISP2 link.&lt;/P&gt;
&lt;P&gt;Since we have two same MX 10 records, is the ISP2 link going to receive emails even if the ISP1 link keeps running.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We do appreciate your config examples and advise.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Mesut&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063538#M147239</guid>
      <dc:creator>Mesut Canbolat</dc:creator>
      <dc:date>2019-03-12T08:50:39Z</dc:date>
    </item>
    <item>
      <title>I am not an expert on DNS</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063539#M147240</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I am not an expert on DNS stuff but below advise is on basis of networking experience:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;How is the design actually. Where are the ISPs terminating and are these 2 ISP active at the same time or one at a time. Please confirm the physical setup.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Also, please confirm if the dns reply consisting of mx record values has both entries if you do dns lookup from either ISP or it has just one mx record corresponding to that ISP. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Ideally, if the mx priority values are same, I would expect traffic to be load balanced, but then that depends where that traffic(smtp) goes(which ISP) and that depends on your physical setup.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;AJ&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 11:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063539#M147240</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-01-27T11:32:31Z</dc:date>
    </item>
    <item>
      <title>Thanks AJ for your reply.</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063540#M147241</link>
      <description>&lt;P&gt;Thanks AJ for your reply.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; O&lt;FONT size="2"&gt;ur physical setup&lt;/FONT&gt; : Asa 5512x&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside0 : Isp1&amp;nbsp;&amp;nbsp; outside1: Isp2&amp;nbsp;&amp;nbsp;&amp;nbsp; inside &amp;nbsp;: &amp;nbsp;MailServer&lt;/P&gt;
&lt;P&gt;Example Ips :&lt;/P&gt;
&lt;P&gt;outside 0 :&amp;nbsp;&amp;nbsp;95.95.95.1 /28&amp;nbsp;&amp;nbsp; Active&lt;/P&gt;
&lt;P&gt;outside 1 :&amp;nbsp;&amp;nbsp; 75.75.75.1 /28&amp;nbsp; Active&amp;nbsp;&amp;nbsp; at the same time. Same Mx 10 Records&lt;/P&gt;
&lt;P&gt;inside : 192.168.1.1 /24&lt;/P&gt;
&lt;P&gt;MailServer : 192.168.1.10 /24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No Local Network No Clients localy connected. All clients are remote clients ousite IMAP connections.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please advise , Thanks&lt;/P&gt;
&lt;P&gt;Mesut&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 17:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063540#M147241</guid>
      <dc:creator>Mesut Canbolat</dc:creator>
      <dc:date>2017-01-27T17:13:04Z</dc:date>
    </item>
    <item>
      <title>Ok, so can I assume that this</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063541#M147242</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Ok, so can I assume that this query is all about inbound access needed by outside located clients to internal exchange using IMAP protocol. Or maybe imap over ssl?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Please confirm.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;AJ&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 19:08:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063541#M147242</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-01-27T19:08:09Z</dc:date>
    </item>
    <item>
      <title>Ok, so can I assume that this</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063542#M147243</link>
      <description>&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;Ok, so can I assume that this query is all about inbound access needed by outside located clients to internal exchange using IMAP protocol. Or maybe imap over ssl?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;Please confirm. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;AJ&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;Yes&amp;nbsp; AJ&amp;nbsp; it is&amp;nbsp; only IMAP connections.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 20:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063542#M147243</guid>
      <dc:creator>Mesut Canbolat</dc:creator>
      <dc:date>2017-01-27T20:01:18Z</dc:date>
    </item>
    <item>
      <title>So, this is my understamding</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063543#M147245</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;So, this is my understamding of your setup, please correct me if I am wrong somewhere:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ISP1 - default gateway with preferred route towards internet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;ISP2 - default gateway with less preferred route towards internet&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In this case, inbound traffic should work for both ISP since reply traffic will follow the same path back as it came in.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Now, as per your scenario, lets say ISP1 fails and ISP2 is handling incoming traffic for both mx records . Now, when the ISP1 comes back up, if the inbound traffic arrives on ISP1, it will work. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;It all depends on how quikcly ISP1 can punt the traffic for ISP1 towards ISP1. ASA will have a limited role to play in there since its a recipient. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Depends on ISP what criteria they have to identify of when the ISP1 is active or down. Looks like a routing question that should be pointed to the ISP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Let me know if I missed out on something or there is some additional questions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 20:39:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063543#M147245</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-01-27T20:39:17Z</dc:date>
    </item>
    <item>
      <title>HELLO AJ</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063544#M147247</link>
      <description>&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;HELLO AJ &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;---------------------------------------------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;So, this is my understamding of your setup, please correct me if I am wrong somewhere:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;ISP1 - default gateway with preferred route towards internet&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;ISP2 - default gateway with less preferred route towards internet&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;In this case, inbound traffic should work for both ISP since reply traffic will follow the same path back as it came in.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;Now, as per your scenario, lets say ISP1 fails and ISP2 is handling incoming traffic for both mx records . Now, when the ISP1 comes back up, if the inbound traffic arrives on ISP1, it will work. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;It all depends on how quikcly ISP1 can punt the traffic for ISP1 towards ISP1. ASA will have a limited role to play in there since its a recipient. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;Depends on ISP what criteria they have to identify of when the ISP1 is active or down. Looks like a routing question that should be pointed to the ISP.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;Let me know if I missed out on something or there is some additional questions.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;**********************************************************************&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; font-size: 10pt;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;Hi AJ ,&amp;nbsp; You did understand everything&amp;nbsp; very well. You are not missing anything else . If you have time could you please&amp;nbsp; try&amp;nbsp;on example&amp;nbsp; setup config. Thanks a lot for your&amp;nbsp; time and advice. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2017 05:48:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063544#M147247</guid>
      <dc:creator>Mesut Canbolat</dc:creator>
      <dc:date>2017-01-28T05:48:36Z</dc:date>
    </item>
    <item>
      <title>Sorry for the delay here. I</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063545#M147249</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Sorry for the delay here. I am having some troubles with support forum notifications. I will search some documents or provide a sample config in a day or two max.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;AJ&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 15:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063545#M147249</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-01-31T15:59:09Z</dc:date>
    </item>
    <item>
      <title>Hi AJ ,</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063546#M147252</link>
      <description>&lt;P&gt;Hi AJ ,&lt;/P&gt;
&lt;P&gt;Thanks for your kindly update. Please take your time . It is not so urgernt at the moment.&lt;/P&gt;
&lt;P&gt;When you are&amp;nbsp; done with your priority jobs . You are most welcome to provide example configs.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Take Care ,&lt;/P&gt;
&lt;P&gt;Mesut&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 16:52:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063546#M147252</guid>
      <dc:creator>Mesut Canbolat</dc:creator>
      <dc:date>2017-01-31T16:52:58Z</dc:date>
    </item>
    <item>
      <title>Ok, here is the scenario:</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063547#M147254</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Ok, here is the scenario:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;inside&amp;nbsp; - &amp;nbsp;lan segment&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;outside - ISP1 and having preferred default gateway&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;outside2 - ISP2 and having less preferred gateway&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Current IP Addresses:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Interface Name IP address Subnet mask Method&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;GigabitEthernet0/0 outside 10.0.99.1 255.255.255.0 manual&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;GigabitEthernet0/1 inside 192.168.129.222 255.255.255.0 manual&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;GigabitEthernet0/3 outside2 11.11.11.1 255.255.255.0 manual&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ciscoasa(config)# sh run route&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;route outside 0.0.0.0 0.0.0.0 10.0.99.2 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;route outside2 0.0.0.0 0.0.0.0 11.11.11.254 254 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Now, we have 1 public ip address on each ISP that inside email server is reachable through. Lets say that 10.0.99.10 (ISP1 mx record) and 11.11.11.10 (ISP2 mx record).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Also assume that inside email server is&amp;nbsp;192.168.129.10&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Lets apply 2 NAT statement on each ISP :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;object network obj-10.0.99.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; host 10.0.99.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;object network obj-192.168.129.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; host 192.168.129.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;object network obj-11.11.11.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; host 11.11.11.10&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;nat (inside,outside) source static obj-192.168.129.10 obj-10.0.99.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;nat (inside,outside) source static obj-192.168.129.10 obj-11.11.11.10&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;nat (inside,outside2) source static obj-192.168.129.10 obj-10.0.99.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;nat (inside,outside2) source static obj-192.168.129.10 obj-11.11.11.10&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;***skipped access-lists, need to be applied as required ports****&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Now, in normal state (when both ISP are active), inbound traffic will work fine through either ISP on any ip address.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Lets say, ISP1 goes down and ISP 2 is active. In this case we would expect traffic to arrive on ISP2. No matter on what ip address it comes on, it will work fine. Lets say that a user on internet resolved the mx record to ip address 10.0.99.10 (which belongs to ISP1), then the traffic needs to arrive till ASA ISP2(thats something ISP needs to do) and then ASA will handle it just fine.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Once, the ISP1 comes back up, then inbound again will work on how the users on internet resolve mx records and where the traffic lands(which ISP).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Please let me know if there are any questions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;FYI, if you wish to add ISP failover feature here, even then this should work. I don't see any challenge as far as ASA is concerned.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;AJ&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 20:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063547#M147254</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-02-02T20:52:35Z</dc:date>
    </item>
    <item>
      <title>Hello Dear AJ ,</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063548#M147255</link>
      <description>&lt;P&gt;Hello Dear AJ ,&lt;/P&gt;
&lt;P&gt;Sorry for my late reply.&amp;nbsp; Many thanks for your&amp;nbsp; example config for my scenario.&lt;/P&gt;
&lt;P&gt;I will be able to deploy this config on our running active&amp;nbsp; asa network at the end of this month&amp;nbsp; when we do&amp;nbsp; half day maintanence.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I will be posting&amp;nbsp; all test results here .&lt;/P&gt;
&lt;P&gt;Once again thank you for all your great effort and support.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best Wishes&lt;/P&gt;
&lt;P&gt;Mesut&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 09:09:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063548#M147255</guid>
      <dc:creator>Mesut Canbolat</dc:creator>
      <dc:date>2017-02-06T09:09:00Z</dc:date>
    </item>
    <item>
      <title>You will also need an SLA</title>
      <link>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063549#M147256</link>
      <description>&lt;P&gt;You will also need an SLA tracker to either track the interface or an IP so that the ASA knows when to insert the backup route. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, since traffic will be expected on both interfaces even when ISP2 is not the active route, you will need to account for asynchronous routing. &amp;nbsp;depending on the ASA version you are running you can do this either by placing interfaces in traffic zones (version 9.3.2 or higher) or tcp bypass. &amp;nbsp;If you are not running a version higher than 9.3.2 then I suggest upgrading and implementing traffic zones as using tcp-bypass can cause security risks.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;sla monitor 123&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; type echo protocol ipIcmpEcho 4.2.2.2 interface outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;sla monitor schedule 123 life forever start-time now&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;track 1 rtr 123 reachability&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;route outside1 0.0.0.0 0.0.0.0 10.0.0.2 1 track 1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;route outside2 0.0.0.0 0.0.0.0 11.0.0.1 254&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;zone outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;interface gig0/1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; description to ISP1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; zone-member outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;interface gig0/2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; description to ISP2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; zone-member outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 10:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/e-mail-server-on-asa/m-p/3063549#M147256</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-02-06T10:04:56Z</dc:date>
    </item>
  </channel>
</rss>

