<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static nat + dual isp in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536144#M600817</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for this nice trick. However,&amp;nbsp; what happens if both links are up, and a client access&amp;nbsp; web server via IP address of backup interface? What route will ASA use in this case? (Default route will point to ISP1, and client request will come through ISP2).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Oct 2010 20:37:16 GMT</pubDate>
    <dc:creator>mirko.veselic</dc:creator>
    <dc:date>2010-10-21T20:37:16Z</dc:date>
    <item>
      <title>Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536138#M600811</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a Cisco ASA 5520 with static nat for webserver. I&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is possible set the Asa 5520 with dual-isp + static nat for web server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alessio&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:55:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536138#M600811</guid>
      <dc:creator>vannucchim</dc:creator>
      <dc:date>2019-03-11T18:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536139#M600812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have 2 statics fo the 2 isp links. The will be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,isp1) zzz yyyy&lt;/P&gt;&lt;P&gt;static (inside,isp2) xxx yyyy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And of course you will need SLA monitoring to fall back between ISPs in case of failures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps,&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 14:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536139#M600812</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-10-18T14:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536140#M600813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i understand correctly, you want to have a static NAT on both your ISP's for that web server and also have dual ISP config ? Please correct me if i am wrong. If i am correct with the above problem description, then all you would need to do is to create a static NAT for the second ISP link but make sure that it is entered after the existing NAT statement for the primary ISP link. This is necessaryas the order of the static statements in the xlate table makes a difference.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 14:16:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536140#M600813</guid>
      <dc:creator>nseshan</dc:creator>
      <dc:date>2010-10-18T14:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536141#M600814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need them to be in order. The right static is going to be chosen based on route look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SLA monitoring you need &lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt; When ISP1 goes down ISP2 route will be used and the translations will be using the ISP2 static.,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that you will have one default route a t a time, but when one goes down the other is going to kick in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 14:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536141#M600814</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-10-18T14:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536142#M600815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; "&gt;Thanks for your support, you were very helpful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alessio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 15:14:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536142#M600815</guid>
      <dc:creator>vannucchim</dc:creator>
      <dc:date>2010-10-18T15:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536143#M600816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark this one as solved, if it is, so that others can benefit in the future.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs,&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 15:28:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536143#M600816</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-10-18T15:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536144#M600817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for this nice trick. However,&amp;nbsp; what happens if both links are up, and a client access&amp;nbsp; web server via IP address of backup interface? What route will ASA use in this case? (Default route will point to ISP1, and client request will come through ISP2).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 20:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536144#M600817</guid>
      <dc:creator>mirko.veselic</dc:creator>
      <dc:date>2010-10-21T20:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536145#M600818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;You have 2 routes. The high priority route is chose while it is up. You only fall back to the low priority when the primary is removed because it failed. So, if the high priority is up, it is preferred. Here is the guide that explains it &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it is clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 21:38:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536145#M600818</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-10-21T21:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536146#M600819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the answer, PK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately I wasn't clear enough. I was talking about outbound traffic from the server to the client (for example - server replying to client's request for web page). But your answer was clear. If both links are up, reply will go over default route (ISP1), not over the backup link (ISP2), right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again.&lt;/P&gt;&lt;P&gt;mirko &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2010 07:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536146#M600819</guid>
      <dc:creator>mirko.veselic</dc:creator>
      <dc:date>2010-10-22T07:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Static nat + dual isp</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536147#M600820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To explain it better, if the inbound request is coming in ISP2 and ISP1 route is up the response will go out ISP1 and you will have asymmetric routing issues. In other words, you can't use ISP1 and 2 at the same time, ISP2 will be used only when 1 is down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2010 13:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-dual-isp/m-p/1536147#M600820</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-10-22T13:45:36Z</dc:date>
    </item>
  </channel>
</rss>

