<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 5510 ISP backup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677383#M558366</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As soon as i took out "route outside 0.0.0.0 0.0.0.0 173.251.14.33 1" this and added " route outside 0.0.0.0 0.0.0.0 173.251.14.33 1 track 1"&amp;nbsp; internet went down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me give you more information how our isp gateway is setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list HOME-REMOTENONAT&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;static (inside,outside) tcp interface smtp Exchange2010 smtp netmask 255.255.255&lt;BR /&gt;.255&lt;BR /&gt;static (inside,outside) tcp interface https Exchange2010 https netmask 255.255.2&lt;BR /&gt;55.255&lt;BR /&gt;static (inside,outside) tcp interface 3389 10.10.10.203389 netmask 255.255.255.2&lt;BR /&gt;55&lt;BR /&gt;access-group 101 in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 114.324.321.33&amp;nbsp; 1&lt;BR /&gt;route inside 10.10.4.0 255.255.255.0 10.10.4.1 1&lt;BR /&gt;route inside 10.10.5.0 255.255.255.0 10.10.5.1 1&lt;BR /&gt;route inside 10.10.6.0 255.255.255.0 10.10.6.1 1&lt;BR /&gt;route inside 10.10.7.0 255.255.255.0 10.10.7.1 1&lt;BR /&gt;route inside 10.10.8.0 255.255.255.0 10.10.8.1 1&lt;BR /&gt;route inside 10.10.9.0 255.255.255.0 10.10.9.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls help, thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Apr 2011 13:30:15 GMT</pubDate>
    <dc:creator>lawsuites</dc:creator>
    <dc:date>2011-04-07T13:30:15Z</dc:date>
    <item>
      <title>Cisco 5510 ISP backup</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677380#M558356</link>
      <description>&lt;P&gt;Hello everyone, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to setup backup ISP in our ASA5510.&amp;nbsp;&amp;nbsp; Right now the the firewall has for defualt gateway following command: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"route outside 0.0.0.0 0.0.0.0 114.324.321.33 1"&amp;nbsp; i am changing this to &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 114.324.321.33 10 track 1&amp;nbsp; ...so i can setup sla monitoring &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as i do the above command and remove the orignal "route outside 0.0.0.0 0.0.0.0 114.324.321.33 1" from asa then internet connection drops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now asa interface Ethernet0/0 has main isp configured and configuring&amp;nbsp; interface Ethernet0/3 as backup. &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; interface Ethernet0/3&lt;BR /&gt; nameif backup&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 114.324.321.34 255.255.255.252&lt;BR /&gt; no shut&lt;BR /&gt;global (backup) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 114.324.321.33 10 track 1 ( Right now in firewall i have" route outside 0.0.0.0 0.0.0.0 114.324.321.33 1 " ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;route backup 0.0.0.0 0.0.0.0&amp;nbsp; 115.283.212.23 20 track 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;track 1 rtr 1 reachability &lt;/P&gt;&lt;P&gt;track 2 rtr 2 reachability &lt;/P&gt;&lt;P&gt;sla monitor 1&lt;BR /&gt;type echo protocol ipIcmpEcho 114.324.321.33 interface outside&lt;BR /&gt;sla monitor schedule 1 life forever start-time now&lt;BR /&gt;sla monitor 2&lt;BR /&gt;type echo protocol ipIcmpEcho 115.283.212.23 interface backup&lt;BR /&gt;sla monitor schedule 2 life forever start-time now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------&lt;/P&gt;&lt;P&gt;Also our firewall has site to site vpn and 1 main ip configured for exchange and remote access.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:17:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677380#M558356</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2019-03-11T20:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ISP backup</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677381#M558357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;ASA/PIX wont allow us to configure default route with same AD.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;You can increase the AD value for the backup default route and apply the TRACK in the primary default route.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Also no need to apply the track to backup default route.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Updated configuration:-&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;i&lt;SPAN style="color: #0000ff;"&gt;nterface Ethernet0/3&lt;BR /&gt;nameif backup&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 114.324.321.34 255.255.255.252&lt;BR /&gt;no shut&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif; color: #0000ff;"&gt;global (backup) 1 interface&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 114.324.321.33 1 track 1&lt;BR /&gt;route backup 0.0.0.0 0.0.0.0&amp;nbsp; 115.283.212.23 254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif; color: #0000ff;"&gt;&lt;BR /&gt;track 1 rtr 1 reachability&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif; color: #0000ff;"&gt;&lt;BR /&gt;sla monitor 1&lt;BR /&gt;type echo protocol ipIcmpEcho 114.324.321.33 interface outside&lt;BR /&gt;sla monitor schedule 1 life forever start-time now&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Karuppu&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 02:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677381#M558357</guid>
      <dc:creator>KARUPPUCHAMY MALAIYANDI</dc:creator>
      <dc:date>2011-04-07T02:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ISP backup</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677382#M558361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Karuppu, thanks for the quick response, will try that and let you know. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 02:44:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677382#M558361</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2011-04-07T02:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ISP backup</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677383#M558366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As soon as i took out "route outside 0.0.0.0 0.0.0.0 173.251.14.33 1" this and added " route outside 0.0.0.0 0.0.0.0 173.251.14.33 1 track 1"&amp;nbsp; internet went down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me give you more information how our isp gateway is setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list HOME-REMOTENONAT&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;static (inside,outside) tcp interface smtp Exchange2010 smtp netmask 255.255.255&lt;BR /&gt;.255&lt;BR /&gt;static (inside,outside) tcp interface https Exchange2010 https netmask 255.255.2&lt;BR /&gt;55.255&lt;BR /&gt;static (inside,outside) tcp interface 3389 10.10.10.203389 netmask 255.255.255.2&lt;BR /&gt;55&lt;BR /&gt;access-group 101 in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 114.324.321.33&amp;nbsp; 1&lt;BR /&gt;route inside 10.10.4.0 255.255.255.0 10.10.4.1 1&lt;BR /&gt;route inside 10.10.5.0 255.255.255.0 10.10.5.1 1&lt;BR /&gt;route inside 10.10.6.0 255.255.255.0 10.10.6.1 1&lt;BR /&gt;route inside 10.10.7.0 255.255.255.0 10.10.7.1 1&lt;BR /&gt;route inside 10.10.8.0 255.255.255.0 10.10.8.1 1&lt;BR /&gt;route inside 10.10.9.0 255.255.255.0 10.10.9.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls help, thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 13:30:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677383#M558366</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2011-04-07T13:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5510 ISP backup</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677384#M558373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any advise on this, pls. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 03:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5510-isp-backup/m-p/1677384#M558373</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2011-04-14T03:32:25Z</dc:date>
    </item>
  </channel>
</rss>

