<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Based Routing to ASA Inside Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612249#M580589</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought that was in fact the case - that it is possible to policy route directly to the ASA interface ip address, but wanted to confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your responses!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 05 Mar 2011 19:42:10 GMT</pubDate>
    <dc:creator>rlesyshyn</dc:creator>
    <dc:date>2011-03-05T19:42:10Z</dc:date>
    <item>
      <title>Policy Based Routing to ASA Inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612245#M580579</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to establish PBR rules that set the ip next-hop to point directly to the inside interface of the ASA5550?&lt;/P&gt;&lt;P&gt;Or, do I need to direct this PBR traffic first to a directly connected router interface and then default route to the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At a high level, here's what we have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISP 1 - with /21 IP Prefix&lt;/LI&gt;&lt;LI&gt;No BGP Routing&lt;/LI&gt;&lt;LI&gt;3845 Edge Router - Default Route to ISP 1&lt;/LI&gt;&lt;LI&gt;PIX535 Firewalls (HA) - Default Route to Edge Router&lt;/LI&gt;&lt;LI&gt;LAN Core/Distribution - Default Route to PIX535 Inside Interface&lt;/LI&gt;&lt;LI&gt;All applications/services use this egress path for PAT/NAT/DMZ/VPN/Etc.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what we are adding:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISP 2 - with /24 IP Prefix&lt;/LI&gt;&lt;LI&gt;No BGP Routing&lt;/LI&gt;&lt;LI&gt;3925E Edge Router - Default Route to ISP 2&lt;/LI&gt;&lt;LI&gt;ASA5550 Firewalls (HA) - Default Route to Edge Router&lt;/LI&gt;&lt;LI&gt;Same connectivity to LAN Core/Distribution&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Goals:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Maintain ISP 1 for now&lt;/LI&gt;&lt;LI&gt;Migrate only end user Internet traffic to ISP 2&lt;/LI&gt;&lt;LI&gt;No disruptions to applications/services using current DefGW to PIX535&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, my question again is how to best use PBR to selectively direct traffic to the ASA inside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please feel free to suggest other methods that might be more appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612245#M580579</guid>
      <dc:creator>rlesyshyn</dc:creator>
      <dc:date>2019-03-11T20:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing to ASA Inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612246#M580581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to be clear you're asking on how to configure PBR on the routers correct?&lt;/P&gt;&lt;P&gt;The reason I ask is because there's no PBR functionality on ASAs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Mar 2011 18:55:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612246#M580581</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-03-05T18:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing to ASA Inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612247#M580583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know how to use PBR and I do realize that PBR is not supported ON the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is can I use PBR to set an ip next-hop that points to the ASA inside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my scenario above, I do not want to make a wholesale default gateway change just yet to route all traffic away from our legacy PIX535.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just want to selectively move traffic on a subnet by subnet to egress the new ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Mar 2011 19:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612247#M580583</guid>
      <dc:creator>rlesyshyn</dc:creator>
      <dc:date>2011-03-05T19:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing to ASA Inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612248#M580587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have a router behind the ASA, you can configure PBR on that router to send a subset of traffic to the ASA's inside interface IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When configuring PBR, you can set the next-hop to be the inside IP of the ASA (the IP, not the actual interface of the ASA) but this should be no problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case it does not matter if the next-hop is an ASA, a router or any other device, you just set the next-hop to the IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Mar 2011 19:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612248#M580587</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-03-05T19:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing to ASA Inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612249#M580589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought that was in fact the case - that it is possible to policy route directly to the ASA interface ip address, but wanted to confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your responses!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Mar 2011 19:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-to-asa-inside-interface/m-p/1612249#M580589</guid>
      <dc:creator>rlesyshyn</dc:creator>
      <dc:date>2011-03-05T19:42:10Z</dc:date>
    </item>
  </channel>
</rss>

