<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Two outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/two-outside-interface/m-p/2356720#M307094</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding the inbound connections will work from both ISPs to this hosts and connections from each ISP will have their return traffic forwarded according to the existing XLATE on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However when the actual server forms a connection outbound it will only use the ISP which holds the current active default route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 15 Dec 2013 17:27:17 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-12-15T17:27:17Z</dc:date>
    <item>
      <title>Two outside interface</title>
      <link>https://community.cisco.com/t5/network-security/two-outside-interface/m-p/2356717#M307090</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have got the cisco ASA 5520 with the following ip address:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example purpose only:&lt;/P&gt;&lt;P&gt;=======================&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Outside5: 8.8.8.0/24 (connected to ISP1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;interface5: 10.10.0.0/16 (Connected to LAN)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;static (interface5,outside5) 8.8.8.8 10.10.10.10 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have got the above scenario and working well on the live environment. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I am planning to add another ISP as follows: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside10: 7.7.7.0/24 (Connected to ISP2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upto this their will be no any trouble. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But will the following statement works ? If it does work how will it route ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (interface5,outside10) 7.7.7.7 10.10.10.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mero&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:18:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-outside-interface/m-p/2356717#M307090</guid>
      <dc:creator>Mero Cisco</dc:creator>
      <dc:date>2019-03-12T03:18:04Z</dc:date>
    </item>
    <item>
      <title>Two outside interface</title>
      <link>https://community.cisco.com/t5/network-security/two-outside-interface/m-p/2356718#M307091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will probably work for the incoming/inbound connections towards the IP address 7.7.7.7. Connection will come through the ISP2 and return traffic will flow through ISP2 also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think however that the host 10.10.10.10 will only form outbound connections through ISP1 if its holding the default route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Dec 2013 14:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-outside-interface/m-p/2356718#M307091</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-12-15T14:27:31Z</dc:date>
    </item>
    <item>
      <title>Two outside interface</title>
      <link>https://community.cisco.com/t5/network-security/two-outside-interface/m-p/2356719#M307093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Will the inbound traffic come from isp1 also. &lt;/P&gt;&lt;P&gt;Actually 10.10.10.10 is the public web server and I want to maintain isp fail over. Will this concept work ? Both public ip will be registered as dns. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Dec 2013 17:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-outside-interface/m-p/2356719#M307093</guid>
      <dc:creator>Mero Cisco</dc:creator>
      <dc:date>2013-12-15T17:17:56Z</dc:date>
    </item>
    <item>
      <title>Two outside interface</title>
      <link>https://community.cisco.com/t5/network-security/two-outside-interface/m-p/2356720#M307094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding the inbound connections will work from both ISPs to this hosts and connections from each ISP will have their return traffic forwarded according to the existing XLATE on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However when the actual server forms a connection outbound it will only use the ISP which holds the current active default route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Dec 2013 17:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-outside-interface/m-p/2356720#M307094</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-12-15T17:27:17Z</dc:date>
    </item>
  </channel>
</rss>

