<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 with two ISPs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633796#M581069</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stumbled upon this. Would this work?&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/docs/DOC-6069&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Mar 2011 23:56:06 GMT</pubDate>
    <dc:creator>craig-mitchell</dc:creator>
    <dc:date>2011-03-01T23:56:06Z</dc:date>
    <item>
      <title>ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633786#M581056</link>
      <description>&lt;P&gt;Could someone point me in the right direction and maybe provide a config example of how to setup an ASA with two Internet connections?  We want to have the ability to send certain traffic over one connection (example http) and everything else over another. Is there a way to do this, and if so, an example config would be greatly appreciated. Thanks. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633786#M581056</guid>
      <dc:creator>craig-mitchell</dc:creator>
      <dc:date>2019-03-11T19:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633787#M581058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Craig&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm sorry to inform you that this cannot be done on the ASA (at least in any straight forward way).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA software does not support Policy-based Routing which is required to complete your requirement. However you can always configure multiple ISPs in an active-passive fashion; as described at the following link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a work-around in some scenarios you can run the ASA box in multiple context mode to achive similar requirements but that is not recommended due to various reasons (complexity, some features like dynamic routing/VPNs not working in virtual fw mode etc.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Feb 2011 09:04:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633787#M581058</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2011-02-26T09:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633788#M581060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Couldn't you use policy based NAT to NAT certain traffic out out a different interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Feb 2011 13:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633788#M581060</guid>
      <dc:creator>craig-mitchell</dc:creator>
      <dc:date>2011-02-26T13:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633789#M581062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use policy-based NAT (it can also be on the same output interface depending on the exact requirement); but there will be no link reliability in this case. What happens when one link fails?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Feb 2011 15:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633789#M581062</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2011-02-26T15:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633790#M581063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Reading the original request, It doesn't sound like failover or redundancy are important criteria in the scenario presented.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Feb 2011 21:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633790#M581063</guid>
      <dc:creator>parr</dc:creator>
      <dc:date>2011-02-26T21:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633791#M581064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, not concerned with failover/redundancy at this point. Can you tell me how I would configure the two static routes for each ISP?  Thanks so much for your help. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 13:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633791#M581064</guid>
      <dc:creator>craig-mitchell</dc:creator>
      <dc:date>2011-02-27T13:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633792#M581065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Craig&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is why i mentioned in my initial post that you won't be able to meet your requirement because PBR is not supported on the ASA: the problem is that one can only configure default routes pointing out one interface on the ASA firewall (and not more); as mentioned in the config guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN class="content"&gt; When defining more than one default route, you must specify the same interface for each entry."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Source: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/asdm64/configuration_guide/route_static.html#wp1128007"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/asdm64/configuration_guide/route_static.html#wp1128007&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And as you know a default route is essential to route internet traffic. If you have any proxy server or router in the transit path; you can fulfull your requirement using those devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 13:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633792#M581065</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2011-02-27T13:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633793#M581066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So what if I setup another default route with a higher metric and policy NATed the traffic I wanted out that new interface?  Would that work?  Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 17:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633793#M581066</guid>
      <dc:creator>craig-mitchell</dc:creator>
      <dc:date>2011-02-27T17:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633794#M581067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry to tell you that will also not work, please see the next paragraph on the same link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;"If you attempt to define more than three equal cost default routes &lt;STRONG&gt;or a&amp;nbsp; default route with a different interface than a previously defined&amp;nbsp; default route, you receive the following message: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A name="wp1123744"&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;&lt;STRONG&gt;"ERROR: Cannot add route entry, possible conflict with existing routes." &lt;/STRONG&gt;&lt;BR /&gt;"&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Farrukh&lt;/PRE&gt;&lt;/DIV&gt;&lt;DIV class="pPreformatted"&gt;&lt;PRE class="pPreformatted"&gt;&lt;A name="wp1150944"&gt;&lt;/A&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 19:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633794#M581067</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2011-02-27T19:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633795#M581068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But it is allowed if I setup route tracking via icmp?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 19:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633795#M581068</guid>
      <dc:creator>craig-mitchell</dc:creator>
      <dc:date>2011-02-27T19:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633796#M581069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stumbled upon this. Would this work?&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/docs/DOC-6069&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 23:56:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633796#M581069</guid>
      <dc:creator>craig-mitchell</dc:creator>
      <dc:date>2011-03-01T23:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633797#M581070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry for the late reply; that solution is definitely worth a try; even tough the solution is a little crude &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Mar 2011 08:15:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633797#M581070</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2011-03-05T08:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633798#M581071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I made this change for port 80 traffic, I could see that it worked. However , it seemed to break internal web traffic between clients and an internal web server (both on the inside network not traversing the firewall). Could this be a proxy arp issue or an icmp redirect issue. The clients default gateway is a cisco router and this router's default gateway is the inside of the asa. The clients, internal web server, core router, and Asa inside interface are all on the same subnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Mar 2011 17:01:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633798#M581071</guid>
      <dc:creator>craig-mitchell</dc:creator>
      <dc:date>2011-03-08T17:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with two ISPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633799#M581072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I doubt this is a proxy ARP issue as it is only supposed to kick in if you are trying to reach an IP address on another subnet and the router replies with his own MAC; it should not occur for traffic on the same subnet. Of course this could be due to mis-configured subnet mask(s) on one or more devices in the concerned network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be easily verified by inspecting the ARP table of both client and server (web); e.g. on windows 'arp -a' will show this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Mar 2011 18:42:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-isps/m-p/1633799#M581072</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2011-03-08T18:42:54Z</dc:date>
    </item>
  </channel>
</rss>

