<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Design Question on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/design-question-on-asa/m-p/1644406#M593257</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree that your assumption is correct with one caveat, unicast RPF must be turned off.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Jan 2011 19:35:40 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2011-01-27T19:35:40Z</dc:date>
    <item>
      <title>Design Question on ASA</title>
      <link>https://community.cisco.com/t5/network-security/design-question-on-asa/m-p/1644405#M593256</link>
      <description>&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/1/6/10616-Drawing1.jpg" alt="Drawing1.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello folks -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an image describing my network topology. As indicated, we have two different ISP's for two different services we provide. Our customers have access to Database servers as well as FTP servers sitting in the DMZ. Customers are connecting over the Internet. ISP1 is supposed to be used for all outbound traffic for the database server, and ISP2 is supposed to be used for all outbound FTP traffic. The connection to both these servers is being intiated by the customers from outside. The firewall has a default route pointing to ISP1.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Since ASA is a stateful firewall, I am assuming all connections coming over ISP2 into the DMZ will be routed back over the ISP2 connection, and not over to ISP1 since that is where the default route is pointing to. Therefore there should not be any assymetric routing that should occur.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my assumption correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/design-question-on-asa/m-p/1644405#M593256</guid>
      <dc:creator>ksarin123_2</dc:creator>
      <dc:date>2019-03-11T19:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Design Question on ASA</title>
      <link>https://community.cisco.com/t5/network-security/design-question-on-asa/m-p/1644406#M593257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree that your assumption is correct with one caveat, unicast RPF must be turned off.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 19:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/design-question-on-asa/m-p/1644406#M593257</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2011-01-27T19:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Design Question on ASA</title>
      <link>https://community.cisco.com/t5/network-security/design-question-on-asa/m-p/1644407#M593259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you explain why unicast RPF must be turned off?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 20:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/design-question-on-asa/m-p/1644407#M593259</guid>
      <dc:creator>ksarin123_2</dc:creator>
      <dc:date>2011-01-27T20:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Design Question on ASA</title>
      <link>https://community.cisco.com/t5/network-security/design-question-on-asa/m-p/1644408#M593260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have provided the option that you are looking for in this document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-13015"&gt;https://supportforums.cisco.com/docs/DOC-13015/#Allowing_outbound_via_ISP1_and_inbound_via_ISP2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jan 2011 02:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/design-question-on-asa/m-p/1644408#M593260</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-28T02:36:12Z</dc:date>
    </item>
  </channel>
</rss>

