<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Since you have IP Sla, ISP-2 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/3735373#M172876</link>
    <description>&lt;P&gt;Hello Syed and Dean,I know this is an old post.I have a similar case .i know how to set up ip sla for dual isps.My question centers on the 'Dns resolution '&lt;BR /&gt;I have a public domain 'lab.com' from a domain provider.i have this subdomain 'call.lab.com ' which resolves to this public ip address 1.1.1.1/27. The host server is sitting on the edge with that public ip add. Cisco router or firewall is not playing any role to minimize nat issues.&lt;BR /&gt;If i have another isp2 2.2.2.2/27,is there anyway i can make the call.lab.com resolves to 1.1.1.1 or 2.2.2.2 in case one of the isps fails.&lt;BR /&gt;In the dns record of the domain provider,can i point call.lab.com to two different public ip address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Oct 2018 06:31:52 GMT</pubDate>
    <dc:creator>collinks2</dc:creator>
    <dc:date>2018-10-30T06:31:52Z</dc:date>
    <item>
      <title>Dual-ISP Public IP Redundancy for a single inside server NATed for Outside Access</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777037#M172869</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Currently I have a 6509 switch which connects to an HA-Pair of 5520's. The 5520's connect to both ISP 1 (12.x.x.x) &amp;amp; ISP 2 (50.x.x.x). &amp;nbsp;I have an inside server farm on 192.168.0.0/24, and many of these servers need to be accessed from the outside, which requires public NATs in my ASA, which I have. However, currently we are only NATing the inside 192.168.0.0/24 farm addresses to available public IP's within the subnet block ISP 1 has given to us on the 12.x.x.x/27 space. An example is below:&lt;/P&gt;
&lt;P&gt;object network corpmobile.domain.com&lt;BR /&gt; host&amp;nbsp;192.168.0.17&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network corpmobile.&lt;/SPAN&gt;&lt;SPAN&gt;domain&lt;/SPAN&gt;&lt;SPAN&gt;.com-public&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;host&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;12.x.xxx.17&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network &lt;SPAN&gt;corpmobile.&lt;/SPAN&gt;&lt;SPAN&gt;domain&lt;/SPAN&gt;&lt;SPAN&gt;.com&lt;/SPAN&gt;&lt;BR /&gt; nat (inside,outside) static &lt;SPAN&gt;corpmobile.&lt;/SPAN&gt;&lt;SPAN&gt;domain&lt;/SPAN&gt;&lt;SPAN&gt;.com-public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;In the event ISP 1 fails, these services will no longer be accessible from the outside, since ISP 2 is on a 50.x.x.x/27 space, and the static NATs for the inside services are&amp;nbsp;on 12.x.x.x/27 (ISP 1, which would be down).&lt;/P&gt;
&lt;P&gt;Is there a way I can configure the ASA to static NAT a single inside server to respond when tried from outside on&amp;nbsp;a 50.x.x.x/27 AND a 12.x.x.x/27 address so that if ISP 1 is down, my services will still be accessible via ISP 2&amp;nbsp;via to 50.x.x.x/27 NAT?&lt;/P&gt;
&lt;P&gt;Drawing of existing topology attached for a visual if needed.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777037#M172869</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2019-03-12T07:13:52Z</dc:date>
    </item>
    <item>
      <title>This document should be very</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777038#M172870</link>
      <description>&lt;P&gt;This document should be very helpful. &amp;nbsp;IP Sla and using backup routes&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118962-configure-asa-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118962-configure-asa-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If your ASA has a default route via ISP-1 then there's no problem. Incase your ISP-1 fails then from the outside to access a specific Server on the inside, you need to reach to&amp;nbsp;&lt;SPAN&gt;50.x.x.x/27. For this you need to have a static NAT and also a route with a higher Admin Distance. You may refer to a similar query in this&amp;nbsp;&lt;A href="https://supportforums.cisco.com/discussion/12760876/pbr-and-static-nat-cisco-asa"&gt;link&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Syed&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 18:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777038#M172870</guid>
      <dc:creator>Syed Taukir</dc:creator>
      <dc:date>2016-02-02T18:27:52Z</dc:date>
    </item>
    <item>
      <title>Hi Syed,</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777039#M172871</link>
      <description>&lt;P&gt;Hi Syed,&lt;/P&gt;
&lt;P&gt;Thanks for replying. I should have mentioned that I do have IP SLA configured already.&lt;/P&gt;
&lt;P&gt;The problem I am having is how to configure the inside server to been seen on the outside as either 12.x.x.x/27 or 50.x.x.x/27. Right now I have:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network corpmobile.domain.com&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;host&amp;nbsp;192.168.0.17&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network corpmobile.domain.com-public&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;host&amp;nbsp;12.x.xxx.17&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network corpmobile.domain.com&lt;BR /&gt;nat (inside,outside) static corpmobile.domain.com-public&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;But if ISP 1 goes down (12.x.x.x/27), then currently, none of my NATs are going to work because those NATs are only accessible when ISP 1 is up, since they are on public addresses on ISP 1's space. &amp;nbsp;So how can I configure the ASA so that my inside IP address can be mapped to two outside addresses; 1 on 12.x.x.x and 1 on 50.x.x.x?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 20:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777039#M172871</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2016-02-02T20:24:13Z</dc:date>
    </item>
    <item>
      <title>Hi Dean,</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777040#M172872</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier, monospace;"&gt;Hi Dean,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier, monospace;"&gt;You can create another object network with the same host. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 10pt;"&gt;=&amp;gt;From the link&amp;nbsp;&lt;STRONG&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/nat_objects.html#wp1103116"&gt;Configuring object NAT&lt;/A&gt;&lt;/STRONG&gt;, it states the following&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 10pt;"&gt;"You can only define a single NAT rule for a given object; if you want to configure multiple NAT rules for an object, you need to create multiple objects with different names that specify the same IP address, for example, &lt;B class="cBold"&gt;object network obj-10.10.10.1-01&lt;/B&gt;, &lt;B class="cBold"&gt;object network obj-10.10.10.1-02&lt;/B&gt;, and so on. "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier, monospace;"&gt;=&amp;gt;You already have the object "corpmobile.domain.com" with host&amp;nbsp;192.168.0.17. You can still create another object with the same host.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;object network corpmobile.domain.com.&lt;STRONG&gt;isp2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;host&amp;nbsp;192.168.0.17&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier, monospace;"&gt;nat(inside,outside) static&amp;nbsp;50.x.x.x&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new, courier, monospace"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;=&amp;gt;If ISP-1 fails then you should access the server on&amp;nbsp;50.x.x.x and a connection will be established as the ASA would have it's default route via ISP-2.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new, courier, monospace"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;=&amp;gt;If you want, you can also access the Server via ISP-1 and ISP-2 at the same time by having 2 default routes via ISP-1 and ISP-2 and one of them having a higher Admin Distance.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new, courier, monospace"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new, courier, monospace"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;HTH&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new, courier, monospace"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Syed Taukir&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier, monospace;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new, courier, monospace"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 13:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777040#M172872</guid>
      <dc:creator>Syed Taukir</dc:creator>
      <dc:date>2016-02-03T13:23:02Z</dc:date>
    </item>
    <item>
      <title>Thanks Syed.  So just to</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777041#M172873</link>
      <description>&lt;P&gt;Thanks Syed. &amp;nbsp;So just to confirm. I can do the following:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network corpmobile.domain.com-isp1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;host 192.168.0.17&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network corpmobile.domain.com-public-isp1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;host 12.x.xxx.17&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network corpmobile.domain.com-isp1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;nat (inside,outside) static corpmobile.domain.com-public-isp1&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;object network corpmobile.domain.com-isp2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;host 192.168.0.17&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network corpmobile.domain.com-public-isp2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;host 50.x.xxx.17&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network corpmobile.domain.com-isp2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;nat (inside,outside) static corpmobile.domain.com-public-isp2&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;And the address that will reply depends on where the default tracked route is pointing. If it is pointed out to ISP 1, it will be seen on 12.x.x.17, if it pointing out to ISP 2, it will be seen on 50.x.x.17.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, the only other problem is what about DNS? ISP 1 is currently the resolver for name-to-IP's. So if ISP 1 goes down, users are still going to enter the same URL, and ISP 1's DNS server is going to reply with a name resolution of that URL still belonging to a 12.x.x.x address.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2016 19:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777041#M172873</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2016-02-04T19:27:02Z</dc:date>
    </item>
    <item>
      <title>Since you have IP Sla, ISP-2</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777042#M172874</link>
      <description>&lt;H6&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 10pt;"&gt;Since you have IP Sla, ISP-2 would kick in once ISP-1 goes down and all new requests would resolve to the DNS reply received over ISP-2 (50.x.x.x).&lt;/SPAN&gt;&lt;/H6&gt;
&lt;H6&gt;&lt;/H6&gt;
&lt;H6&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 10pt;"&gt;HTH&lt;/SPAN&gt;&lt;/H6&gt;
&lt;H6&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 10pt;"&gt;Syed&lt;/SPAN&gt;&lt;/H6&gt;</description>
      <pubDate>Thu, 04 Feb 2016 19:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777042#M172874</guid>
      <dc:creator>Syed Taukir</dc:creator>
      <dc:date>2016-02-04T19:39:35Z</dc:date>
    </item>
    <item>
      <title>Ok, so basically I need to</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777043#M172875</link>
      <description>&lt;P&gt;Ok, so basically I need to have both ISP's create outside DNS entires for each of my inside servers that are getting NATed, and the DNS resolution that will reply to outside internet requests will be dependent on which route is active via the IP SLA right?&lt;/P&gt;
&lt;P&gt;No dynamic DNS or fat piping in the cloud would be needed?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2016 20:59:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/2777043#M172875</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2016-02-04T20:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Since you have IP Sla, ISP-2</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/3735373#M172876</link>
      <description>&lt;P&gt;Hello Syed and Dean,I know this is an old post.I have a similar case .i know how to set up ip sla for dual isps.My question centers on the 'Dns resolution '&lt;BR /&gt;I have a public domain 'lab.com' from a domain provider.i have this subdomain 'call.lab.com ' which resolves to this public ip address 1.1.1.1/27. The host server is sitting on the edge with that public ip add. Cisco router or firewall is not playing any role to minimize nat issues.&lt;BR /&gt;If i have another isp2 2.2.2.2/27,is there anyway i can make the call.lab.com resolves to 1.1.1.1 or 2.2.2.2 in case one of the isps fails.&lt;BR /&gt;In the dns record of the domain provider,can i point call.lab.com to two different public ip address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 06:31:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-public-ip-redundancy-for-a-single-inside-server-nated/m-p/3735373#M172876</guid>
      <dc:creator>collinks2</dc:creator>
      <dc:date>2018-10-30T06:31:52Z</dc:date>
    </item>
  </channel>
</rss>

