<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dual ISP with static NAT for each ISP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dual-isp-with-static-nat-for-each-isp/m-p/2434775#M268867</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding Static NAT for one internal host towards 2 different ISPs should work just fine as long as the connections are only formed from the ISP links towards the internal network. In this case the ASA should be able to use the existing connection and translation formed through the ISP in question to forward the return traffic correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However if there is anything that requires the internal host to initiate connection towards the external networks then it will naturally only use the ISP which holds the default route at that point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to your NAT configuration. They seem to be basic Static NAT configurations with Manual NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure this with Auto NAT / Network Object NAT also but you just need to configure 2 different NAT as you can hold multiple &lt;STRONG&gt;"nat"&lt;/STRONG&gt; statements under one &lt;STRONG&gt;"object"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you could have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network HOST-ISP-1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host &lt;INTERNAL ip=""&gt;&lt;/INTERNAL&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,isp1) static &lt;PUBLIC ip="" isp1=""&gt;&lt;/PUBLIC&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network HOST-ISP-2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host &lt;INTERNAL ip=""&gt;&lt;/INTERNAL&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,isp2) static &lt;PUBLIC ip="" isp2=""&gt;&lt;/PUBLIC&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you could try the above configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the connections still dont work I would monitor the logs for any blocked connections or other problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 02 Mar 2014 16:50:20 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2014-03-02T16:50:20Z</dc:date>
    <item>
      <title>Dual ISP with static NAT for each ISP</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-with-static-nat-for-each-isp/m-p/2434774#M268866</link>
      <description>&lt;P&gt;We recently went from single ISP on our ASA to dual ISPs with failover using object tracking.&amp;nbsp; Dynamic NAT is working great with both ISP.&amp;nbsp; Using this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inf_inside,inf_ISP1) after-auto source dynamic PAT_Networks interface&lt;/P&gt;&lt;P&gt;nat (inf_inside,inf_ISP2) after-auto source dynamic PAT_Networks interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However static NAT is proving more challenging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BEFORE:&lt;/P&gt;&lt;P&gt;object network host1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (inf_inside,inf_ISP1) static publicIP1_ISP1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AFTER:&lt;BR /&gt;nat (inf_inside,inf_ISP1) source static host1 publicIP1_ISP1&lt;BR /&gt;nat (inf_inside,inf_ISP2) source static host1 publicIP2_ISP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With object NAT it works great no matter which ISP I use.&amp;nbsp; However, to my&amp;nbsp; knowlege I can't use two different NATs using object NAT therefore I setup the two individual NAT statements shown in AFTER section. I also have identical ACLs on both ISP interfaces to allow needed traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The host here happens to be a DVR.&amp;nbsp; When using the individual NAT statements the web management page only partly loads or does not load at all.&amp;nbsp; Video clients cannot connect at all.&amp;nbsp; Basically you can see the DVR is kinda there and responding but not working as it should.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something I am missing or should be doing differently?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-with-static-nat-for-each-isp/m-p/2434774#M268866</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2019-03-12T03:52:03Z</dc:date>
    </item>
    <item>
      <title>Dual ISP with static NAT for each ISP</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-with-static-nat-for-each-isp/m-p/2434775#M268867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding Static NAT for one internal host towards 2 different ISPs should work just fine as long as the connections are only formed from the ISP links towards the internal network. In this case the ASA should be able to use the existing connection and translation formed through the ISP in question to forward the return traffic correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However if there is anything that requires the internal host to initiate connection towards the external networks then it will naturally only use the ISP which holds the default route at that point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to your NAT configuration. They seem to be basic Static NAT configurations with Manual NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure this with Auto NAT / Network Object NAT also but you just need to configure 2 different NAT as you can hold multiple &lt;STRONG&gt;"nat"&lt;/STRONG&gt; statements under one &lt;STRONG&gt;"object"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you could have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network HOST-ISP-1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host &lt;INTERNAL ip=""&gt;&lt;/INTERNAL&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,isp1) static &lt;PUBLIC ip="" isp1=""&gt;&lt;/PUBLIC&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network HOST-ISP-2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host &lt;INTERNAL ip=""&gt;&lt;/INTERNAL&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,isp2) static &lt;PUBLIC ip="" isp2=""&gt;&lt;/PUBLIC&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you could try the above configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the connections still dont work I would monitor the logs for any blocked connections or other problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Mar 2014 16:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-with-static-nat-for-each-isp/m-p/2434775#M268867</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-03-02T16:50:20Z</dc:date>
    </item>
    <item>
      <title>Dual ISP with static NAT for each ISP</title>
      <link>https://community.cisco.com/t5/network-security/dual-isp-with-static-nat-for-each-isp/m-p/2434776#M268868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I should have thought about using two objects!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Jouni.&amp;nbsp; I will try later on this week and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 01:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dual-isp-with-static-nat-for-each-isp/m-p/2434776#M268868</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2014-03-05T01:25:49Z</dc:date>
    </item>
  </channel>
</rss>

