<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Static route by interface or destination in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-route-by-interface-or-destination/m-p/1795408#M530160</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ben &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you really need is PBR (Policy Based Routing) which unfortunately is not supported on the ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may be able to do something with NAT but it would need testing as VOIP/videoconferencing doesn't always work with NAT. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically you use poilicy NAT so when traffic is sent from vlan to vlan 4 you NAT the source vlan 1 ip addresses. Then at site2 you can add a specific route for the nat subnet which would point to the QOS&amp;nbsp; connection. This would mean you could still have your existing vlan 1 route at site 2 pointing to the VPN tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Sep 2011 18:40:49 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2011-09-22T18:40:49Z</dc:date>
    <item>
      <title>Static route by interface or destination</title>
      <link>https://community.cisco.com/t5/network-security/static-route-by-interface-or-destination/m-p/1795407#M530158</link>
      <description>&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Is it possible to assign a static route to an interface and not globally on a ASA 5510 ver 8.3. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;I have two links between my offices one for Data via a VPN and one for video traffic which is a secure connection with QOS end to end. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;All interfaces are on the same security level of 100 except Outside which is 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Office 1 Interfaces ASA 5510&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vOffice1Data&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.40.1.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vOffice1Video&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.40.2.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vInterOffice&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.40.5.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (QOS&amp;nbsp; connection Between Offices)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50Mb&amp;nbsp;&amp;nbsp;&amp;nbsp; Internet / Site to Site VPN between offices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Office 2 Interfaces ASA 5510&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vOffice2Data&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.40.2.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vOffice2Video&amp;nbsp; 10.40.4.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vInterOffice&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.40.5.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Secure connection Between Offices)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50Mb&amp;nbsp;&amp;nbsp;&amp;nbsp; Internet / Site to Site VPN between offices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;All &lt;STRONG&gt;local&lt;/STRONG&gt; VLAN’s route between themselves OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Also the following far end routing is working OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN 1 --- VLAN 2 Both Ways via Site to Site VPN &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN 3 --- VLAN 4 Both Ways via E-Pipe using a static Route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN 1 &amp;amp;,2 are used for data&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;VLAN 3 &amp;amp; 4 are used for Video Conferencing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;We are adding desktop videoconferencing to our end points so we need to be able to route traffic from the local Data network destined to the far end video network via the E-Pipe. All local data VLAN’s to far end data VLAN’s should still route traffic through the VPN connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;As an example if I had my laptop connected to VLAN 1 I should be able to access far end VLAN 2 via Site To Site VPN and also be able to access far end VLAN 4 via the E-Pipe route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Is this possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;At the moment if I try and access data from VLAN 1 to VLAN 4 it gets to the destination ok going through the static route and over the vInterOffice connection but the problem is VLAN 4 returning the traffic. This fails because there is no static route back to VLAN 1. If I create a static route from Office 2 to VLAN 1 then it will route all my data traffic over it as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Any suggestions? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-by-interface-or-destination/m-p/1795407#M530158</guid>
      <dc:creator>BenTwentyEleven</dc:creator>
      <dc:date>2019-03-11T21:28:50Z</dc:date>
    </item>
    <item>
      <title>Static route by interface or destination</title>
      <link>https://community.cisco.com/t5/network-security/static-route-by-interface-or-destination/m-p/1795408#M530160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ben &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you really need is PBR (Policy Based Routing) which unfortunately is not supported on the ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may be able to do something with NAT but it would need testing as VOIP/videoconferencing doesn't always work with NAT. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically you use poilicy NAT so when traffic is sent from vlan to vlan 4 you NAT the source vlan 1 ip addresses. Then at site2 you can add a specific route for the nat subnet which would point to the QOS&amp;nbsp; connection. This would mean you could still have your existing vlan 1 route at site 2 pointing to the VPN tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 18:40:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-by-interface-or-destination/m-p/1795408#M530160</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-09-22T18:40:49Z</dc:date>
    </item>
    <item>
      <title>Static route by interface or destination</title>
      <link>https://community.cisco.com/t5/network-security/static-route-by-interface-or-destination/m-p/1795409#M530162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input. Unfortunately I couldn’t get your NAT solution working. Hopefully Cisco will bring out PBR on the ASA soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Sep 2011 14:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-by-interface-or-destination/m-p/1795409#M530162</guid>
      <dc:creator>BenTwentyEleven</dc:creator>
      <dc:date>2011-09-25T14:25:44Z</dc:date>
    </item>
  </channel>
</rss>

