<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic many thanks Eng.Philip for in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dual-isp/m-p/2909977#M153107</link>
    <description>&lt;P&gt;many thanks Eng.Philip for your response ,&amp;nbsp;I have ASA 5585-x running version 9.4 which has PBR feature.&lt;/P&gt;
&lt;P&gt;As i know the DMZ servers can have two NAT one per ISP so if the link on ISP1 goes down the servers can still have access to internet.&lt;/P&gt;
&lt;P&gt;i think i can do the deployment with PBR feature is it right ?&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jun 2016 23:36:39 GMT</pubDate>
    <dc:creator>asheemy</dc:creator>
    <dc:date>2016-06-11T23:36:39Z</dc:date>
    <item>
      <title>ASA DUAL ISP</title>
      <link>https://community.cisco.com/t5/network-security/asa-dual-isp/m-p/2909975#M153105</link>
      <description>&lt;P&gt;have ASA deployment with dual ISP I need to use one ISP for WSA Proxy and VPN any connect only and the second one for DMZ Servers and if one ISP GOES DOWN the second one will take place.&lt;BR /&gt;Please share a good design to ache achieve this deployment as best practice.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 01:09:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dual-isp/m-p/2909975#M153105</guid>
      <dc:creator>asheemy</dc:creator>
      <dc:date>2019-03-13T01:09:56Z</dc:date>
    </item>
    <item>
      <title>You need to use PBR to do</title>
      <link>https://community.cisco.com/t5/network-security/asa-dual-isp/m-p/2909976#M153106</link>
      <description>&lt;P&gt;You need to use PBR to do this, which needs quite new software. &amp;nbsp;Note that this only works for outbound traffic selection. &amp;nbsp;It is unlikely both ISPs will allow you to use the other ISPs IP address space on their circuit.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What this means is you could create outbound redundancy, but not inbound. &amp;nbsp;So if the link to the ISP that has given you address space for the DMZ goes down, all services in the DMZ that the Internet accesses will also go down.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What model ASA are you using, and what software version are you using?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jun 2016 22:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dual-isp/m-p/2909976#M153106</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-06-11T22:52:25Z</dc:date>
    </item>
    <item>
      <title>many thanks Eng.Philip for</title>
      <link>https://community.cisco.com/t5/network-security/asa-dual-isp/m-p/2909977#M153107</link>
      <description>&lt;P&gt;many thanks Eng.Philip for your response ,&amp;nbsp;I have ASA 5585-x running version 9.4 which has PBR feature.&lt;/P&gt;
&lt;P&gt;As i know the DMZ servers can have two NAT one per ISP so if the link on ISP1 goes down the servers can still have access to internet.&lt;/P&gt;
&lt;P&gt;i think i can do the deployment with PBR feature is it right ?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jun 2016 23:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dual-isp/m-p/2909977#M153107</guid>
      <dc:creator>asheemy</dc:creator>
      <dc:date>2016-06-11T23:36:39Z</dc:date>
    </item>
    <item>
      <title>If you don't do NAT, you can</title>
      <link>https://community.cisco.com/t5/network-security/asa-dual-isp/m-p/2909978#M153108</link>
      <description>&lt;P&gt;If&amp;nbsp;you don't do NAT, you can use PBR to make the routing work.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can probably make it work with PBR and NAT. &amp;nbsp;I have not done that combination before. &amp;nbsp;It sounds complicated.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jun 2016 04:32:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dual-isp/m-p/2909978#M153108</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-06-12T04:32:43Z</dc:date>
    </item>
  </channel>
</rss>

