<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5506 vlan routing help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3802663#M7105</link>
    <description>&lt;P&gt;Thank you for your reply - i managed to get this far already yesterday and it seems to be working. Now the problem is that when i have set dhcp server for interface it stops working.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Feb 2019 10:56:02 GMT</pubDate>
    <dc:creator>J.Newman</dc:creator>
    <dc:date>2019-02-15T10:56:02Z</dc:date>
    <item>
      <title>ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799015#M7081</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;i need a little help to get my configuration working&lt;/P&gt;&lt;P&gt;I have 3 ISP's which all land on one switch&lt;/P&gt;&lt;P&gt;i have an asa5506x which needs to route each vlan to specific isp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so the configuration should look something like this:&lt;/P&gt;&lt;P&gt;external:&lt;/P&gt;&lt;P&gt;isp1 (gw address 10.10.10.1)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;isp2 (gw address 10.10.10.2)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;isp3 (gw address 10.10.10.3)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;asa:&lt;/P&gt;&lt;P&gt;outside: 10.10.10.100&lt;/P&gt;&lt;P&gt;vlan 100 - ip range 192.168.100.0/24&amp;nbsp; - routed to isp1&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;vlan 200 - ip range 192.168.200.0/24&amp;nbsp; - routed to isp2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;vlan 300 - ip range 192.168.300.0/24&amp;nbsp; - routed to isp3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;currently all my tests result in all vlan's beeing routed to isp1&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:47:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799015#M7081</guid>
      <dc:creator>J.Newman</dc:creator>
      <dc:date>2020-02-21T16:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799043#M7083</link>
      <description>if I understood correctly you need to use PBR. Route traffic based on your source route. Here is a sample configuration

object network sub-vlan-100
subnet 192.168.100.0 255.255.255.0
object network sub-vlan-200
subnet 192.168.200.0 255.255.255.0
object network sub-vlan-300
subnet 192.168.300.0 255.255.255.0
!
###### Assuming isp1 interface is named outside1, isp2 --&amp;gt; outside2, isp3 --&amp;gt;outside3
!
object network obj-isp1
nat (sub-vlan-100, outside) dynamic interface
object network obj-isp2
nat (sub-vlan-200, outside) dynamic interface
object network obj-isp3
nat (sub-vlan-300, outside) dynamic interface
!
access-list out1 extended permit 192.168.100.0  255.255.255.0 any
access-list out2 extended permit 192.168.200.0  255.255.255.0 any
access-list out3 extended permit 192.168.300.0  255.255.255.0 any
!
route-map pbr-map permit 10
match ip address out1
set ip next-hop 10.10.10.1
route-map pbr-map permit 20
match ip address out2
set ip next-hop 10.10.10.1
route-map pbr-map permit 30
match ip address out3
set ip next-hop 10.10.10.3
!
interface &lt;ISP_INTERFACE&gt;
policy-route route-map pbr-map
!
route outside 0 0 10.10.10.1 1
route outside 0 0 10.10.10.2 2
route outside 0 0 10.10.10.3 3
!

&lt;/ISP_INTERFACE&gt;</description>
      <pubDate>Mon, 11 Feb 2019 10:00:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799043#M7083</guid>
      <dc:creator>socratesp1980</dc:creator>
      <dc:date>2019-02-11T10:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799057#M7085</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in asa i currently have only one outside interface and it is called "outside" which&amp;nbsp;is connected to a "dumb" switch.&lt;/P&gt;&lt;P&gt;the switch is connected to three different isp's.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 10:25:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799057#M7085</guid>
      <dc:creator>J.Newman</dc:creator>
      <dc:date>2019-02-11T10:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799178#M7090</link>
      <description>&lt;P&gt;Look at&amp;nbsp; below example guide, adding to other post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.networkstraining.com/cisco-asa-policy-based-routing-pbr/" target="_blank"&gt;https://www.networkstraining.com/cisco-asa-policy-based-routing-pbr/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also consider using IP SLA, if any of the link fails route to different ISP, if not the traffic will be black-holed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 13:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799178#M7090</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-02-11T13:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799635#M7096</link>
      <description>&lt;P&gt;I am puzzled about what the original poster describes "have only one outside interface and it is called "outside" which&amp;nbsp;is connected to a "dumb" switch.&amp;nbsp;the switch is connected to three different isp's"&lt;/P&gt;
&lt;P&gt;If there are 3 different ISPs I would certainly assume that each ISP has its own unique public IP. I do not see any way for ASA5506 to be able to talk to 3 different public IP connected to outside interface. If this were IOS and we could use secondary address then it could work. But that is not supported on ASA. I do not see any way to get 3 different ISP connected to dumb switch connected to one ASA interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 22:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3799635#M7096</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2019-02-11T22:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3801630#M7099</link>
      <description>&lt;P&gt;i will try to explain a little bit more:&lt;/P&gt;&lt;P&gt;there is a router that&amp;nbsp;first accepts all connections from isp's and the creates an internal network with&amp;nbsp;different ip representing each isp. These ip's are used by many "secondary" routers (like this asa). Please have a look at my great paint drawing attached to this post.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 09:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3801630#M7099</guid>
      <dc:creator>J.Newman</dc:creator>
      <dc:date>2019-02-14T09:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3801957#M7104</link>
      <description>&lt;P&gt;Thank you for the explanation. This is an unusual environment but now we have a better understanding of it. Based on what we know now I do agree that the solution that you need is to configure Policy Based Routing on the ASA. In the route map for PBR you could match to subnet 1 and set ip next-hop as address of ISP 1, match to subnet 2 and set ip next-hop as address of ISP 2, and match on subnet 3 and set ip next-hop as address of ISP 3.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 15:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3801957#M7104</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2019-02-14T15:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3802663#M7105</link>
      <description>&lt;P&gt;Thank you for your reply - i managed to get this far already yesterday and it seems to be working. Now the problem is that when i have set dhcp server for interface it stops working.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 10:56:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3802663#M7105</guid>
      <dc:creator>J.Newman</dc:creator>
      <dc:date>2019-02-15T10:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3802743#M7109</link>
      <description>&lt;P&gt;Glad you got it to the point where it seems to be working. I am not clear how setting dhcp server would impact &amp;nbsp;PBR unless the DHCP server is changing addresses so that they do not match the acl for PBR. Perhaps you could supply some detail about what you are trying to do?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 13:30:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3802743#M7109</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2019-02-15T13:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3807392#M7112</link>
      <description>&lt;P&gt;Sorry, if my explanation was not clear. if i remove pbr then my computers are getting address from dhcp that has been configured on asa to vlan interface. if i set pbr then computers in this vlan interface stop getting address from dhcp server configured in asa.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 07:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3807392#M7112</guid>
      <dc:creator>J.Newman</dc:creator>
      <dc:date>2019-02-22T07:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 vlan routing help</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3807758#M7114</link>
      <description>&lt;P&gt;Thanks for the explanation. Since we do not have any details of what you are doing it is difficult to know exactly what the issue is. But it seems logical that something in the operation of PBR is interfering with DHCP. Perhaps you could revise the acl that you use to identify traffic for PBR and deny packets related to DHCP?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I correct in understanding that you have several vlans (and therefore several subnets) on your ASA? And so there would be several DHCP scopes? And that you are applying PBR to the interfaces for those several vlans? Perhaps you could post some details about this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 15:55:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-vlan-routing-help/m-p/3807758#M7114</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2019-02-22T15:55:48Z</dc:date>
    </item>
  </channel>
</rss>

