<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CISCO ASA 5510 source basing routing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578156#M393784</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, all!&lt;/P&gt;&lt;P&gt;several organizations wants to place their equipment and servers in my datacenter. They want to use the same resource - 10.3.1.5. I want to connect their servers and VPN-gates via my CISCO ASA 5510. When the organization was the only on ASA was static route "10.3.1.5 via 10.200.1.2". But now this decision doesnt work. Organization1 need to go to 10.3.1.5 via VPN-gate 10.200.1.2. Organization2 need to go to 10.3.1.5 via 10.200.2.2. I cannot connect teir servers and VPN-gates directly. I should do it via ASA 5510.&lt;/P&gt;&lt;P&gt;I need some thing like IOS PBR (more precisely - routing based on source address). Could you advice me how I can configure scheme in attachement on my ASA? May be it will be a kind of NAT?&lt;/P&gt;&lt;P&gt;Note: Also I need to give access to VPN-gates from other networks (NET 1 - NET n)&lt;/P&gt;&lt;P&gt;here is the network scheme &lt;A class="loading" href="https://docs.google.com/drawings/d/1twHdJRDImVcjC_cqYpAeIQuzvAJK2ym-NLylEAw-hOA/edit" title="https://docs.google.com/drawings/d/1twHdJRDImVcjC_cqYpAeIQuzvAJK2ym-NLylEAw-hOA/edit"&gt;https://docs.google.com/drawings/d/1twHdJRDImVcjC_cqYpAeIQuzvAJK2ym-NLylEAw-hOA/edit&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 23 Dec 2012 17:10:52 GMT</pubDate>
    <dc:creator>Dmitriy Popov</dc:creator>
    <dc:date>2012-12-23T17:10:52Z</dc:date>
    <item>
      <title>CISCO ASA 5510 source basing routing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578156#M393784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, all!&lt;/P&gt;&lt;P&gt;several organizations wants to place their equipment and servers in my datacenter. They want to use the same resource - 10.3.1.5. I want to connect their servers and VPN-gates via my CISCO ASA 5510. When the organization was the only on ASA was static route "10.3.1.5 via 10.200.1.2". But now this decision doesnt work. Organization1 need to go to 10.3.1.5 via VPN-gate 10.200.1.2. Organization2 need to go to 10.3.1.5 via 10.200.2.2. I cannot connect teir servers and VPN-gates directly. I should do it via ASA 5510.&lt;/P&gt;&lt;P&gt;I need some thing like IOS PBR (more precisely - routing based on source address). Could you advice me how I can configure scheme in attachement on my ASA? May be it will be a kind of NAT?&lt;/P&gt;&lt;P&gt;Note: Also I need to give access to VPN-gates from other networks (NET 1 - NET n)&lt;/P&gt;&lt;P&gt;here is the network scheme &lt;A class="loading" href="https://docs.google.com/drawings/d/1twHdJRDImVcjC_cqYpAeIQuzvAJK2ym-NLylEAw-hOA/edit" title="https://docs.google.com/drawings/d/1twHdJRDImVcjC_cqYpAeIQuzvAJK2ym-NLylEAw-hOA/edit"&gt;https://docs.google.com/drawings/d/1twHdJRDImVcjC_cqYpAeIQuzvAJK2ym-NLylEAw-hOA/edit&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Dec 2012 17:10:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578156#M393784</guid>
      <dc:creator>Dmitriy Popov</dc:creator>
      <dc:date>2012-12-23T17:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5510 source basing routing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578157#M393787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PBR hasn't been supported in the past on the ASA platform, and I don't believe that's changed, nor have I heard of any plans to do so in the future. I suspect you'd have to work a router into the topology to perform that function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John Meggers&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Dec 2012 19:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578157#M393787</guid>
      <dc:creator>jmeggers</dc:creator>
      <dc:date>2012-12-23T19:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5510 source basing routing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578158#M393793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because this is a VPN you use an acl with source and destination address. You set peers in those crypto maps. There is no reason this wont work from what I understand. Your next hop gate way is till the same for routing correct?  You are just changing the peer address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone, please excuse any typos.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex Jerrold&lt;/P&gt;&lt;P&gt;Systems Engineer&lt;/P&gt;&lt;P&gt;CCIE# 18957&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="cid:4ECA9437-D615-4DEE-AFA4-581EB8087528@nexusis.com"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;1 678 837 2335&amp;lt;tel:&lt;/EM&gt;1%20678%20837%202335&amp;gt;&lt;/P&gt;&lt;P&gt;alex.jerrold@nexusis.com&amp;lt;mailto:alex.jerrold@nexusis.com&amp;gt;&lt;/P&gt;&lt;P&gt;www.nexusis.com&amp;lt;http://www.nexusis.com/&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Collaboration  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Data Center  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Borderless Networks  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Business Video  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Managed Services.&lt;/P&gt;&lt;P&gt;Nexus IS Inc. designs, builds and supports complete end-to-end technology solutions designed to help organizationsConnect to their customers, Collaborate to achieve their vision, and Create innovative solutions to business problems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Dec 2012 20:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578158#M393793</guid>
      <dc:creator>hjerrold1</dc:creator>
      <dc:date>2012-12-23T20:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5510 source basing routing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578159#M393795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in this task I only need the decision to sent traffic with destination ip 10.3.1.5 from 10.255.1.1/29 via 10.200.1.2 and from 10.255.2.1/29 via 10.200.2.2&lt;/P&gt;&lt;P&gt;after that VPN devices spit packets out to right host&lt;/P&gt;&lt;P&gt;How can I solve it on ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Dec 2012 22:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578159#M393795</guid>
      <dc:creator>Dmitriy Popov</dc:creator>
      <dc:date>2012-12-23T22:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5510 source basing routing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578160#M393799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the asa is not doing VPN. Then you are correct. No real way to do this on asa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone, please excuse any typos.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex Jerrold&lt;/P&gt;&lt;P&gt;Systems Engineer&lt;/P&gt;&lt;P&gt;CCIE# 18957&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="cid:4ECA9437-D615-4DEE-AFA4-581EB8087528@nexusis.com"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;1 678 837 2335&amp;lt;tel:&lt;/EM&gt;1%20678%20837%202335&amp;gt;&lt;/P&gt;&lt;P&gt;alex.jerrold@nexusis.com&amp;lt;mailto:alex.jerrold@nexusis.com&amp;gt;&lt;/P&gt;&lt;P&gt;www.nexusis.com&amp;lt;http://www.nexusis.com/&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Collaboration  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Data Center  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Borderless Networks  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Business Video  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Managed Services.&lt;/P&gt;&lt;P&gt;Nexus IS Inc. designs, builds and supports complete end-to-end technology solutions designed to help organizationsConnect to their customers, Collaborate to achieve their vision, and Create innovative solutions to business problems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Dec 2012 23:51:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578160#M393799</guid>
      <dc:creator>hjerrold1</dc:creator>
      <dc:date>2012-12-23T23:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5510 source basing routing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578161#M393801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex, what do you think about full NAT of &lt;SPAN style="font-family: arial; font-size: 12px; background-color: #ffffff;"&gt;10.255.1.1&lt;/SPAN&gt; to &lt;SPAN style="font-family: arial; font-size: 12px; background-color: #ffffff;"&gt;10.200.1.2&lt;/SPAN&gt; and 10.3.1.5 on iface Eth0/0.1 to &lt;SPAN style="font-family: arial; font-size: 12px; background-color: #ffffff;"&gt;10.200.1.2&lt;/SPAN&gt;? Can it be working decision? if all traffic from net &lt;SPAN style="font-family: arial; font-size: 12px; background-color: #ffffff;"&gt;10.255.1.1&lt;/SPAN&gt;/29 really forwarded to vpn-gate &lt;SPAN style="font-family: arial; font-size: 12px; background-color: #ffffff;"&gt;10.200.1.2&lt;/SPAN&gt; then it will be the answer I think..&lt;/P&gt;&lt;P&gt;and the same actions on second organisation servers and vpn-gate...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 00:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578161#M393801</guid>
      <dc:creator>Dmitriy Popov</dc:creator>
      <dc:date>2012-12-24T00:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5510 source basing routing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578162#M393803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a config and diagram!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone, please excuse any typos.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex Jerrold&lt;/P&gt;&lt;P&gt;Systems Engineer&lt;/P&gt;&lt;P&gt;CCIE# 18957&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="cid:4ECA9437-D615-4DEE-AFA4-581EB8087528@nexusis.com"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;1 678 837 2335&amp;lt;tel:&lt;/EM&gt;1%20678%20837%202335&amp;gt;&lt;/P&gt;&lt;P&gt;alex.jerrold@nexusis.com&amp;lt;mailto:alex.jerrold@nexusis.com&amp;gt;&lt;/P&gt;&lt;P&gt;www.nexusis.com&amp;lt;http://www.nexusis.com/&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Collaboration  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Data Center  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Borderless Networks  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Business Video  &lt;A href="cid:image002.png@01CDBEAA.F12D2D80"&gt;&lt;/A&gt;   Managed Services.&lt;/P&gt;&lt;P&gt;Nexus IS Inc. designs, builds and supports complete end-to-end technology solutions designed to help organizationsConnect to their customers, Collaborate to achieve their vision, and Create innovative solutions to business problems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 00:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-source-basing-routing/m-p/3578162#M393803</guid>
      <dc:creator>hjerrold1</dc:creator>
      <dc:date>2012-12-24T00:29:39Z</dc:date>
    </item>
  </channel>
</rss>

