<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA with dual ISP and two public ranges in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136285#M394847</link>
    <description>&lt;P&gt;Hi there,&lt;BR /&gt;&lt;BR /&gt;I have one ASA connecting to two ISP. Each provides me a public ip range.&lt;BR /&gt;I want to publish some servers on ip1 from isp1, and some others on ip2 from isp 2. Im using snat. Each ISP does reverse path checks, so I cant have assymetric routing.&lt;BR /&gt;I can see inbound traffic will not be a problem, but what about (from the servers to the clients)?&lt;BR /&gt;Response traffic from ip1 should leave to default gw on isp1, and the one from ip2 should leave to default gw on isp2.&lt;BR /&gt;Am I able to do this it with the ASA?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Ps.: i dont actually have this scenario today so cant try this out.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:31:03 GMT</pubDate>
    <dc:creator>Ricardo Duarte</dc:creator>
    <dc:date>2019-03-12T00:31:03Z</dc:date>
    <item>
      <title>ASA with dual ISP and two public ranges</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136285#M394847</link>
      <description>&lt;P&gt;Hi there,&lt;BR /&gt;&lt;BR /&gt;I have one ASA connecting to two ISP. Each provides me a public ip range.&lt;BR /&gt;I want to publish some servers on ip1 from isp1, and some others on ip2 from isp 2. Im using snat. Each ISP does reverse path checks, so I cant have assymetric routing.&lt;BR /&gt;I can see inbound traffic will not be a problem, but what about (from the servers to the clients)?&lt;BR /&gt;Response traffic from ip1 should leave to default gw on isp1, and the one from ip2 should leave to default gw on isp2.&lt;BR /&gt;Am I able to do this it with the ASA?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Ps.: i dont actually have this scenario today so cant try this out.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136285#M394847</guid>
      <dc:creator>Ricardo Duarte</dc:creator>
      <dc:date>2019-03-12T00:31:03Z</dc:date>
    </item>
    <item>
      <title>ASA with dual ISP and two public ranges</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136286#M394848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Presently it is not possible to load balance traffic between two ISP links on an ASA. The reason being, there can only be one default route configured on the ASA.&lt;/P&gt;&lt;P&gt;You can achieve your requirement with PBR feature but ASA will not support the PBR , you need to have router to configure PBR. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration example is given on below link &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-13015"&gt;https://supportforums.cisco.com/docs/DOC-13015&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Safwan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Dec 2012 22:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136286#M394848</guid>
      <dc:creator>Muhammed Safwan</dc:creator>
      <dc:date>2012-12-01T22:32:47Z</dc:date>
    </item>
    <item>
      <title>ASA with dual ISP and two public ranges</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136287#M394849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ricardo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as all the connections are innitiated on the outside interface, yes it will work....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the ASA will see the connection being innitiated on ISP2 interface he will send the reply packet out that same interface ( even if the ISP1 is the primary) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if the servers innitiate the connection. I mean sends the first SYN packet, they will go out using ISP1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Dec 2012 23:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136287#M394849</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-12-01T23:05:13Z</dc:date>
    </item>
    <item>
      <title>ASA with dual ISP and two public ranges</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136288#M394850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;jcarvaja, can you tell me how to implement that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a similar situation (but I am not using ISPs, or public addresses).&lt;/P&gt;&lt;P&gt;I have 2 server LANs connected to the ASA, and 2 links to 2 different gateways. Default Gateway is GW1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users can already connect to LAN 1(using the link to GW1). I want them to be able to connect to LAN 2, using the link to GW2.&lt;/P&gt;&lt;P&gt;The incoming traffic arrives at the ASA from the GW2, and is sent to the LAN2.&lt;/P&gt;&lt;P&gt;However, the returning traffic arrives at ASA and is sent to GW1 (because GW1 is the default gateway).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't use static routes because users will use the same source IP addresses to connect to LAN1 and LAN2.&lt;/P&gt;&lt;P&gt;I can't use PBR (to define the gateway based on source IP address) because ASA doesn't support it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, when I test connections to the LAN2 I can't see any connections in "show conn", perhaps they only show up only when the complete handshake is done?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate if someone tell me if this can be accomplished, and how. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 15:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136288#M394850</guid>
      <dc:creator>RuiMeireles</dc:creator>
      <dc:date>2013-06-28T15:39:49Z</dc:date>
    </item>
    <item>
      <title>ASA with dual ISP and two public ranges</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136289#M394851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can U elaborate this a littlebit more:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A diagram&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What you trying to accomplish exactly &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. &lt;BR /&gt; &lt;BR /&gt;For this community that's as important as a thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Jun 2013 04:17:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136289#M394851</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-29T04:17:33Z</dc:date>
    </item>
    <item>
      <title>ASA with dual ISP and two public ranges</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136290#M394853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ricardo, Rui,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe that acheiveing your requriments can be done only by &lt;SPAN style="text-decoration: underline;"&gt;outside PAT&lt;/SPAN&gt; at one of the gateways (ISPs) so as to make all incoming traffic via one GW appear as (patted to) a single IP in the same range of the subnet between ASA and that GW, hence the return traffic (from LAN to Internet) will be routed based on a directly-connected route overriding the static route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this answers your question.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Mashal Alshboul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Jun 2013 06:14:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136290#M394853</guid>
      <dc:creator>malshbou</dc:creator>
      <dc:date>2013-06-29T06:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with dual ISP and two public ranges</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136291#M394855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;Hi there. I solved my problem using (what I think is) Dynamic Identity NAT.&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;Note: My ASA is running firmware 8.2. With 8.3 and forward NAT commands would be different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;# Default route to GW1&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;route GW1 0.0.0.0 0.0.0.0 &lt;GW1_IP&gt; 1&lt;/GW1_IP&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;# Default route to GW2 with higher metric&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;route GW2 0.0.0.0 0.0.0.0 &lt;GW2_IP&gt; 254&lt;/GW2_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;sysopt noproxyarp LAN2&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;static (LAN2,GW2) &lt;LAN2_SUBNET&gt; &lt;LAN2_SUBNET&gt; netmask &lt;LAN2_MASK&gt;&lt;/LAN2_MASK&gt;&lt;/LAN2_SUBNET&gt;&lt;/LAN2_SUBNET&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;Now TCP and UDP connections that are originated by the users with destination to LAN2 will:&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;- arrive at ASA via link to GW2&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;- go to LAN2&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;- return to the ASA&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;- be forwarded to GW2, not using the default route to GW1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt; background: white;"&gt;This is not working with ICMP, however. And connections with origin in LAN2 addresses and destination &lt;USERS network=""&gt; won't work either (obviously).&lt;/USERS&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 13:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-dual-isp-and-two-public-ranges/m-p/2136291#M394855</guid>
      <dc:creator>RuiMeireles</dc:creator>
      <dc:date>2013-07-01T13:59:47Z</dc:date>
    </item>
  </channel>
</rss>

