<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trouble with source nat with backup and primary ISP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/trouble-with-source-nat-with-backup-and-primary-isp/m-p/4029184#M31526</link>
    <description>&lt;P&gt;I have these 2 dynamic statements for primary outside ISP and secondary as backupisp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (any,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network obj_any2&lt;/P&gt;&lt;P&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (any,backupisp) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem I am running into is my primary "outside" has an IPSLA and failing over to backupisp but then voip phones and other devices lose internet connection until I do a&amp;nbsp;clear conn address and then devices moves back to outside PAT.&amp;nbsp; Is there a source PAT timer I can set?&amp;nbsp; Or does my dynamic source nat need to be more specific?&amp;nbsp; Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2020 18:09:56 GMT</pubDate>
    <dc:creator>iverson.justin</dc:creator>
    <dc:date>2020-02-13T18:09:56Z</dc:date>
    <item>
      <title>Trouble with source nat with backup and primary ISP</title>
      <link>https://community.cisco.com/t5/network-security/trouble-with-source-nat-with-backup-and-primary-isp/m-p/4029184#M31526</link>
      <description>&lt;P&gt;I have these 2 dynamic statements for primary outside ISP and secondary as backupisp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (any,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network obj_any2&lt;/P&gt;&lt;P&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (any,backupisp) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem I am running into is my primary "outside" has an IPSLA and failing over to backupisp but then voip phones and other devices lose internet connection until I do a&amp;nbsp;clear conn address and then devices moves back to outside PAT.&amp;nbsp; Is there a source PAT timer I can set?&amp;nbsp; Or does my dynamic source nat need to be more specific?&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 18:09:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-with-source-nat-with-backup-and-primary-isp/m-p/4029184#M31526</guid>
      <dc:creator>iverson.justin</dc:creator>
      <dc:date>2020-02-13T18:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble with source nat with backup and primary ISP</title>
      <link>https://community.cisco.com/t5/network-security/trouble-with-source-nat-with-backup-and-primary-isp/m-p/4029199#M31549</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You can tweak the timeout values, e.g:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;ASA-DC-1/pri/act(config-network-object)# &lt;STRONG&gt;show run | inc timeout&lt;/STRONG&gt;&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;/PRE&gt;&lt;P&gt;Alternatively you could implement an EEM script on the ASA that tracks the primary route, when this fails over to the backup link then takes an action to clear the connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 18:21:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-with-source-nat-with-backup-and-primary-isp/m-p/4029199#M31549</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-02-13T18:21:23Z</dc:date>
    </item>
  </channel>
</rss>

