<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Jouni, Thank you for in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610667#M197563</link>
    <description>&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for sharing above info. Certainly it helps.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jan 2015 07:48:25 GMT</pubDate>
    <dc:creator>Ajay Koorata</dc:creator>
    <dc:date>2015-01-28T07:48:25Z</dc:date>
    <item>
      <title>ASA 5520 Source based Routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610663#M197559</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Hi Friends,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;I am using an ASA 5520 (Software Version 7.0(8)) and having a challenge with routing. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;I have 3 interfaces - Trust, Untrust and Untrust-1 with Security levels set to 100, 0 and 25 respectively.&amp;nbsp; Trust is our LAN network, Untrust is connected to Internet and Untrust-1 is connected to our corporate office via Leased Line. The default route is pointed towards Untrust-1 and all LAN traffic (Trust) traverse via this link.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Now, certain users accessing specific application started complaining about slowness while they connect to a remote server and that traffic traverse via corporate office.&amp;nbsp; So to isolate the connectivity b/w branch and corporate office, I was exploring options to directly route all the traffic from those machines via Untrust interface which is directly connected to Internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Hence need expert view regarding the same something similar to Source Based Routing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Thanks in Advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Ajay&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610663#M197559</guid>
      <dc:creator>Ajay Koorata</dc:creator>
      <dc:date>2019-03-12T05:24:17Z</dc:date>
    </item>
    <item>
      <title>Hi, Have you considered</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610664#M197560</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you considered changing the default route to point to the &lt;STRONG&gt;Untrust&lt;/STRONG&gt; interface and having specific routes for the &lt;STRONG&gt;Untrust-1&lt;/STRONG&gt; interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your software level is quite old. In the newer softwares you are able to (or atleast were previously able to) configure NAT so that it would act as Policy Based Routing as the NAT could override the routing table when choosing the egress interface for traffic. You could have a NAT configuration that would apply to your situation too (forward all traffic from certain hosts through a specific interface)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have seen some similiar configurations in the older software levels (8.2 and below) but they are very limited in their possibilities. I am not even sure you can do anything with your current software level. ASA does not have any official Policy Based Routing capability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2015 11:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610664#M197560</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-27T11:55:07Z</dc:date>
    </item>
    <item>
      <title>Hi Jouni, Thanks for sharing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610665#M197561</link>
      <description>&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for sharing your thoughts ... IOS upgrade is in pipeline and will be doing that by next week. Meanwhile b/w on &lt;STRONG&gt;Untrust&lt;/STRONG&gt; is limited compared to &lt;STRONG&gt;Untrust-1. &lt;/STRONG&gt;Moreover this is a specific user-case wherein only 4 to 6 users are having the issue.&lt;/P&gt;&lt;P&gt;Also, appreciate if you could share more details on NAT solution mentioned above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2015 12:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610665#M197561</guid>
      <dc:creator>Ajay Koorata</dc:creator>
      <dc:date>2015-01-27T12:51:44Z</dc:date>
    </item>
    <item>
      <title>Hi, Here is a link to an</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610666#M197562</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a link to an older discussion related to similiar situation than yours. Or a discussion where I list a couple of example configurations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/discussion/11892151/asa-nat-dual-uplinks-pbr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem with the NAT is that some software newer software levels don't seem to handle it the same way. I have used it succesfully on 8.4(5) and 9.1(1) software levels I think but some newer software levels it has not worked. I can probably test this on some of the newest software levels if there is need for anyone to get a confirmation if this works or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Naturally you will also have to consider if you were to go down this path that even if it did work there is no guarantee it would work after some update or there might perhaps be some unforseen problems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But as I said this is only possible in a new software level.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wrote a document in start of 2013 regarding the new NAT configuration format. Perhaps it might be of some help if you device to upgrade your ASA to the newer software levels (8.3 or above). Heres a link to the document:&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/132066/asa-nat-83-nat-operation-and-configuration-format-cli&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2015 13:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610666#M197562</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-27T13:08:22Z</dc:date>
    </item>
    <item>
      <title>Hi Jouni, Thank you for</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610667#M197563</link>
      <description>&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for sharing above info. Certainly it helps.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2015 07:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-source-based-routing/m-p/2610667#M197563</guid>
      <dc:creator>Ajay Koorata</dc:creator>
      <dc:date>2015-01-28T07:48:25Z</dc:date>
    </item>
  </channel>
</rss>

