<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA 5510 - Split connection: client on connection1 and ser in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-split-connection-client-on-connection1-and-server/m-p/2414583#M270533</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Jouni said, you can't have two active default gateways on an ASA.&amp;nbsp; But I am curious as to your routing statements.&amp;nbsp; Was that just a quick copy paste?&amp;nbsp; you would configure the route statements for which network you are trying to reach and which interface those networks are reachable through and the next hop IP you will send the traffic to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But for your needs I would recommend having a router infront of the ASA that does all routing, PBR, QoS (if needed) etc. and then just use the ASA for traffic filtering.&amp;nbsp; Ofcourse this is all subject to your budget.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Feb 2014 10:02:27 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2014-02-06T10:02:27Z</dc:date>
    <item>
      <title>Cisco ASA 5510 - Split connection: client on connection1 and server on connection2</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-split-connection-client-on-connection1-and-server/m-p/2414580#M270519</link>
      <description>&lt;P&gt;I have a Cisco ASA 5510 configured in routed mode and i want to split internet traffic:&lt;BR /&gt;-client (192.168.42.0 255.255.255.128) on CONNECTION1&lt;BR /&gt;-server (192.168.42.224 255.255.255.224) on CONNECTION2&lt;BR /&gt;Is it possible with this configuration?&lt;BR /&gt;*&lt;BR /&gt;*&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;nameif CONNECTION1&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 33.33.33.33 255.255.255.248&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;nameif CONNECTION2&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 44.44.44.44 255.255.255.248 &lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;nameif LAN&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.42.1 255.255.255.0&lt;BR /&gt;*&lt;BR /&gt;*&lt;BR /&gt;global (CONNECTION1) 2 interface&lt;BR /&gt;global (CONNECTION2) 1 interface&lt;BR /&gt;nat (LAN) 1 192.168.42.224 255.255.255.224&lt;BR /&gt;nat (LAN) 2 192.168.42.0 255.255.255.128&lt;BR /&gt;*&lt;BR /&gt;*&lt;BR /&gt;route CONNECTION1 192.168.42.0 255.255.255.128 33.33.33.33 2&lt;BR /&gt;route CONNECTION2 192.168.42.224 255.255.255.224 44.44.44.44 1&lt;/P&gt;&lt;P&gt;i need to know this befor buying the second connection!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-split-connection-client-on-connection1-and-server/m-p/2414580#M270519</guid>
      <dc:creator>e.irrera</dc:creator>
      <dc:date>2019-03-12T03:38:50Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510 - Split connection: client on connection1 and ser</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-split-connection-client-on-connection1-and-server/m-p/2414581#M270524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like you must be running 8.2, based on those NAT statements. They look correct to me, but I haven't tested them out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think the route statements are correct, because an ASA can't route to itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 07:42:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-split-connection-client-on-connection1-and-server/m-p/2414581#M270524</guid>
      <dc:creator>jshojayi</dc:creator>
      <dc:date>2014-02-06T07:42:23Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510 - Split connection: client on connection1 and ser</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-split-connection-client-on-connection1-and-server/m-p/2414582#M270529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA in your situation will follow its routing table and it cant have 2 default route at the same time. There is some ways to use the NAT in the older software to split the traffic but its not really flexible. Flexible as in splitting all traffic from a single host to the specific ISP. (atleast to my undertanding)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The newer software levels (which you are not using) has possibilities to use the NAT to have one LAN/host use ISP-1 and one LAN/host use ISP-2. Depending how old your ASA5510 is this might mean a RAM upgrade to support the new software and would also mean that current ASAs configuration would need to be converted to the new software. If its a simple configuration then there should be no big problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though I would imagine that this is not an officially supported way (using NAT) to doing this on the ASA even though the NAT operation is described in documentation clearly that it should follow this logic and enable using NAT to forward traffic where you want rather than where the routing table is showing. There are some problems in the newer softwares where this doesnt work at all. (Even though according to all documentation it should)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the original ASA5500 Series this seems to work fine in the 8.4(x) software levels. Personally I have used 8.4(5) when I have labbed the setups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 07:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-split-connection-client-on-connection1-and-server/m-p/2414582#M270529</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-06T07:54:28Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510 - Split connection: client on connection1 and ser</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-split-connection-client-on-connection1-and-server/m-p/2414583#M270533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Jouni said, you can't have two active default gateways on an ASA.&amp;nbsp; But I am curious as to your routing statements.&amp;nbsp; Was that just a quick copy paste?&amp;nbsp; you would configure the route statements for which network you are trying to reach and which interface those networks are reachable through and the next hop IP you will send the traffic to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But for your needs I would recommend having a router infront of the ASA that does all routing, PBR, QoS (if needed) etc. and then just use the ASA for traffic filtering.&amp;nbsp; Ofcourse this is all subject to your budget.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 10:02:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-split-connection-client-on-connection1-and-server/m-p/2414583#M270533</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-06T10:02:27Z</dc:date>
    </item>
  </channel>
</rss>

