<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Load Balancing using Virtual IP on DMZ interface of 5520 ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/load-balancing-using-virtual-ip-on-dmz-interface-of-5520-asa/m-p/1876368#M458949</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pratik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA does not support having 1 global/translated IP address on the outside mapped to multiple local/real IP addresses on the DMZ. If it did, the ASA would have no way of deciding if traffic destined to X.X.X.X is really meant for 10.15.1.2 or 10.15.1.3. For this scenario, you should use a dedicated load balancer or a router that supports policy-based routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Feb 2012 20:50:14 GMT</pubDate>
    <dc:creator>mirober2</dc:creator>
    <dc:date>2012-02-29T20:50:14Z</dc:date>
    <item>
      <title>Load Balancing using Virtual IP on DMZ interface of 5520 ASA</title>
      <link>https://community.cisco.com/t5/network-security/load-balancing-using-virtual-ip-on-dmz-interface-of-5520-asa/m-p/1876367#M458942</link>
      <description>&lt;P&gt;We want to achieve a load balancing scenario using Virtual IP on DMZ interface on a Cisco ASA 5520.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPs we are going to use on DMZ are 10.15.1.2 and 10.15.1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These IPs are going to be NATted to all inside IPs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say our outside IP is X.X.X.X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This IP points to 10.15.1.2 and 10.15.1.3 with .2 being the primary and .3 being the secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I hit the outside IP, it should point me to .2 and that .2 should take me to the inside IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need configuration assistance with that.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/load-balancing-using-virtual-ip-on-dmz-interface-of-5520-asa/m-p/1876367#M458942</guid>
      <dc:creator>Pratik Prajapati</dc:creator>
      <dc:date>2019-03-11T22:33:45Z</dc:date>
    </item>
    <item>
      <title>Load Balancing using Virtual IP on DMZ interface of 5520 ASA</title>
      <link>https://community.cisco.com/t5/network-security/load-balancing-using-virtual-ip-on-dmz-interface-of-5520-asa/m-p/1876368#M458949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pratik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA does not support having 1 global/translated IP address on the outside mapped to multiple local/real IP addresses on the DMZ. If it did, the ASA would have no way of deciding if traffic destined to X.X.X.X is really meant for 10.15.1.2 or 10.15.1.3. For this scenario, you should use a dedicated load balancer or a router that supports policy-based routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 20:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/load-balancing-using-virtual-ip-on-dmz-interface-of-5520-asa/m-p/1876368#M458949</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2012-02-29T20:50:14Z</dc:date>
    </item>
  </channel>
</rss>

