<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Policy Based Routing in Cisco ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618289#M197052</link>
    <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;I want to connect three&amp;nbsp;internet&amp;nbsp;connections (connected to three different ISPs)&amp;nbsp;to my Cisco ASA firewall, accordingly I want to configure the ASA to route traffic based on the source subnet.&lt;/P&gt;&lt;P&gt;Let's say that my network is divided into three different VLANs with different subnets addresses as shown below:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;VLAN 10 -&amp;gt; 10.0.10.0/24&lt;/LI&gt;&lt;LI&gt;VLAN 20 -&amp;gt; 10.0.20.0/24&lt;/LI&gt;&lt;LI&gt;VLAN 30 -&amp;gt; 10.0.30.0/24&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Also,&amp;nbsp;the internet connection are connected to below Outside interfaces on the ASA:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISP1 -&amp;gt; Outside1&lt;/LI&gt;&lt;LI&gt;ISP2 -&amp;gt; Outside2&lt;/LI&gt;&lt;LI&gt;ISP3 -&amp;gt; Outside3&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;My target is to configure the ASA to route Internet traffic&amp;nbsp;based on the source subnet as mentioned below:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Internet traffic sourced from VLAN10 (10.0.10.0/24) to be routed through ISP1 (Outside1)&lt;/LI&gt;&lt;LI&gt;Internet traffic sourced from VLAN20 (10.0.20.0/24) to be routed through ISP2 (Outside2)&lt;/LI&gt;&lt;LI&gt;Internet traffic sourced from VLAN30 (10.0.30.0/24) to be routed through ISP3 (Outside3)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any ideas ??????&lt;/P&gt;&lt;P&gt;Appreciate your feedback.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Begad Ahmed&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:30:20 GMT</pubDate>
    <dc:creator>begad.nashaat</dc:creator>
    <dc:date>2019-03-12T05:30:20Z</dc:date>
    <item>
      <title>Policy Based Routing in Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618289#M197052</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;I want to connect three&amp;nbsp;internet&amp;nbsp;connections (connected to three different ISPs)&amp;nbsp;to my Cisco ASA firewall, accordingly I want to configure the ASA to route traffic based on the source subnet.&lt;/P&gt;&lt;P&gt;Let's say that my network is divided into three different VLANs with different subnets addresses as shown below:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;VLAN 10 -&amp;gt; 10.0.10.0/24&lt;/LI&gt;&lt;LI&gt;VLAN 20 -&amp;gt; 10.0.20.0/24&lt;/LI&gt;&lt;LI&gt;VLAN 30 -&amp;gt; 10.0.30.0/24&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Also,&amp;nbsp;the internet connection are connected to below Outside interfaces on the ASA:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISP1 -&amp;gt; Outside1&lt;/LI&gt;&lt;LI&gt;ISP2 -&amp;gt; Outside2&lt;/LI&gt;&lt;LI&gt;ISP3 -&amp;gt; Outside3&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;My target is to configure the ASA to route Internet traffic&amp;nbsp;based on the source subnet as mentioned below:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Internet traffic sourced from VLAN10 (10.0.10.0/24) to be routed through ISP1 (Outside1)&lt;/LI&gt;&lt;LI&gt;Internet traffic sourced from VLAN20 (10.0.20.0/24) to be routed through ISP2 (Outside2)&lt;/LI&gt;&lt;LI&gt;Internet traffic sourced from VLAN30 (10.0.30.0/24) to be routed through ISP3 (Outside3)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any ideas ??????&lt;/P&gt;&lt;P&gt;Appreciate your feedback.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Begad Ahmed&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:30:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618289#M197052</guid>
      <dc:creator>begad.nashaat</dc:creator>
      <dc:date>2019-03-12T05:30:20Z</dc:date>
    </item>
    <item>
      <title>The ASA is not capable of</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618290#M197053</link>
      <description>&lt;P&gt;The ASA is not capable of policy-based routing. At least not in the actual versions.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2015 13:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618290#M197053</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-02-15T13:36:00Z</dc:date>
    </item>
    <item>
      <title>Hi Karsten, Any workaround to</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618291#M197054</link>
      <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any workaround to deploy this configuration on the ASA ??&lt;/P&gt;&lt;P&gt;What are the versions capable to support this type of configuration ???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Begad Ahmed&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2015 13:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618291#M197054</guid>
      <dc:creator>begad.nashaat</dc:creator>
      <dc:date>2015-02-15T13:43:46Z</dc:date>
    </item>
    <item>
      <title>You can possibly accomplish</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618292#M197055</link>
      <description>&lt;P&gt;You can possibly accomplish it with multiple contexts or multiple virtual ASAs (ASAv product).&lt;/P&gt;&lt;P&gt;On&amp;nbsp;a single context physical ASA it is not currently&amp;nbsp;possible.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2015 18:01:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618292#M197055</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-02-15T18:01:44Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin !!Is it</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618293#M197056</link>
      <description>&lt;P&gt;Thanks Marvin !!&lt;/P&gt;&lt;P&gt;Is it possible to provide me with&amp;nbsp;sample configuration for&amp;nbsp;multiple contexts ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2015 18:47:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618293#M197056</guid>
      <dc:creator>begad.nashaat</dc:creator>
      <dc:date>2015-02-15T18:47:46Z</dc:date>
    </item>
    <item>
      <title>You're welcome.Cisco has some</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618294#M197057</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;&lt;P&gt;Cisco has some very nice examples already. See &lt;A href="http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/99131-multiple-context.html"&gt;this one for example&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Note that multiple context require separate licensing - they are not automatically included. "show version" will show your current licensing active on the ASA.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2015 18:55:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618294#M197057</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-02-15T18:55:55Z</dc:date>
    </item>
    <item>
      <title>Just to add, that with ASA</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618295#M197058</link>
      <description>&lt;P&gt;Just to add, that with ASA-version 9.4(1), policy-based routing is now supported. This is from the &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html"&gt;release-notes&lt;/A&gt;:&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 11px; margin: 1px 0em 6px; line-height: normal;"&gt;Policy Based Routing (PBR) is a mechanism by which traffic is routed through specific paths with a specified QoS using ACLs. ACLs let traffic be classified based on the content of the packet’s Layer 3 and Layer 4 headers. This solution lets administrators provide QoS to differentiated traffic, distribute interactive and batch traffic among low-bandwidth, low-cost permanent paths and high-bandwidth, high-cost switched paths, and allows Internet service providers and other organizations to route traffic originating from various sets of users through well-defined Internet connections.&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 11px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-128803"&gt;&lt;/A&gt;We introduced the following commands:&amp;nbsp;&lt;B class="cBold"&gt;set ip next-hop verify-availability, set ip next-hop, set ip next-hop recursive, set interface, set ip default next-hop, set default interface, set ip df, set ip dscp, policy-route route-map, show policy-route, debug policy-route&lt;/B&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 02 Apr 2015 05:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-in-cisco-asa/m-p/2618295#M197058</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-04-02T05:15:36Z</dc:date>
    </item>
  </channel>
</rss>

