<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Were you able to use PBR? If in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916154#M171399</link>
    <description>&lt;P&gt;Were you able to use PBR? If so which statement worked for you?&lt;/P&gt;</description>
    <pubDate>Wed, 12 Apr 2017 12:43:38 GMT</pubDate>
    <dc:creator>DSMCisco2010</dc:creator>
    <dc:date>2017-04-12T12:43:38Z</dc:date>
    <item>
      <title>Policy based routing in ASA 9.4+ Dual WAN link</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916153#M171396</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using a Cisco ASA 5515x on 9.4(3) code&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem:&lt;/P&gt;
&lt;P&gt;I have a private wireless network 192.168.0.x/20. I do not want to split this large subnet as I always have at least 700 clients connected to this network at any one time (24/7) and do not want to take it down.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently I have (1) 100M-up/20M-down WAN link for Internet traffic only. I am rate-limiting per user bandwidth amount to 1M.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a second WAN 100M-up/20M-down WAN link that I want to utilize for internet access.&amp;nbsp; I already have these links and do not want to spend any more money to upgrade one of them to larger link.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both of these links are from the same carrier. They were originally purchased at different times for different users within same organization.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These WAN links will connect to my ASA5515x.&lt;/P&gt;
&lt;P&gt;I think PBR may provide solution.&lt;/P&gt;
&lt;P&gt;I want to employ PBR and use both links for the Internet connection.&lt;/P&gt;
&lt;P&gt;I want the PBR to divide traffic between both WAN links.&lt;/P&gt;
&lt;P&gt;I think by using an extended acl and specifying destination networks, I can utilize both links.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If one of the WAN links is down, all traffic will use the other link. I want to make sure after down links comes back up, it will resume as primary for the specified range.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I want an SLA to monitor the WAN gateway(s) in order to trigger the failover.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to specify that destinations 1.x.x.x – 9.x.x.x use WAN link 1 as primary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list acl_1 extended permit ip any 1.0.0.0 9.255.255.255&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to specify that destinations 11.x.x.x – 126.x.x.x use WAN link 1 as primary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list acl_1 extended permit ip any 11.0.0.0 115.255.255.255&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to specify that destinations 129.x.x.x – 169.x.x.x use WAN link 2 as primary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list acl_2 extended permit ip any 129.0.0.0 30&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .255.255.255&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to specify that destinations 172.32.x.x – 191.x.x.x use WAN link 2 as primary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list acl_2 extended permit ip any 172.32.0.0 19.255.255.255&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to specify that destinations 192.0.3.x – 192.88.98.255 use WAN link 2 as primary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list acl_2 extended permit ip any 192.0.3.x – 0.88.96.255&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to specify that destinations 192.88.100.x – 192.167.255.255 use WAN link 2 as primary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list acl_2 extended permit ip any 192.88.100.0 79.255.255.255&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to specify that destinations 192.169.x.x – 198.17.255.255 use WAN link 2 as primary&lt;/P&gt;
&lt;P&gt;I want to specify that destinations 192.198.20.x – 223.255.255.255 use WAN link 2 as primary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;
&lt;P&gt;(config-if)# policy-route route-map GuestNet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nameif Outside-2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;security-level 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;ip address 173.a.b.c&amp;nbsp; 255.255.255.252&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nameif Outside-2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;security-level 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;ip address 173.d.e.f&amp;nbsp; 255.255.255.252&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;route-map GuestNet permit 10&lt;/P&gt;
&lt;P&gt;(config-route-map)#match ip address acl_1&lt;/P&gt;
&lt;P&gt;(config-route-map)#set ip next-hop 173.a.b.c&lt;/P&gt;
&lt;P&gt;or &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;set ip next-hop verify-availability 173.a.b.c 1 track 1&lt;/P&gt;
&lt;P style="padding-left: 120px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN&gt;set ip next-hop verify-availability 173.d.e.f 2 track 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;route-map GuestNet permit 20&lt;/P&gt;
&lt;P&gt;(config-route-map)#match ip address acl_2&lt;/P&gt;
&lt;P&gt;(config-route-map)#set ip next-hop 173.d.e.f&lt;/P&gt;
&lt;P&gt;or &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;set ip next-hop verify-availability 173.d.e.f 1 track 1&lt;/P&gt;
&lt;P style="padding-left: 120px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN&gt;set ip next-hop verify-availability 173.a.b.c 2 track 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;route-map GuestNet permit 30&lt;/P&gt;
&lt;P&gt;(config-route-map)#set ip interface Null0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please review the config and advise if this is a good working solution. Please also advise on any improvements needed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916153#M171396</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2019-03-12T07:57:11Z</dc:date>
    </item>
    <item>
      <title>Were you able to use PBR? If</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916154#M171399</link>
      <description>&lt;P&gt;Were you able to use PBR? If so which statement worked for you?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 12:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916154#M171399</guid>
      <dc:creator>DSMCisco2010</dc:creator>
      <dc:date>2017-04-12T12:43:38Z</dc:date>
    </item>
    <item>
      <title>Did the null0 statement work</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916155#M171401</link>
      <description>&lt;P&gt;Did the null0 statement work for you?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 12:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916155#M171401</guid>
      <dc:creator>DavidMeyer321</dc:creator>
      <dc:date>2017-04-12T12:47:36Z</dc:date>
    </item>
    <item>
      <title>Dave</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916156#M171403</link>
      <description>&lt;P&gt;Dave&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for the response. This scenario above has not been implemented as yet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 13:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916156#M171403</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2017-04-12T13:49:33Z</dc:date>
    </item>
    <item>
      <title>DSM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916157#M171404</link>
      <description>&lt;P&gt;DSM&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for the response. This scenario above has not been implemented as yet.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 13:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-asa-9-4-dual-wan-link/m-p/2916157#M171404</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2017-04-12T13:49:57Z</dc:date>
    </item>
  </channel>
</rss>

