<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple WAN connections, one firewall? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-wan-connections-one-firewall/m-p/1365478#M744857</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will best if you terminate your ISP links in router and do a Policy based routing based on the incoming traffic from LAN.I would suggest you to make setup in the below manner&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISP1 -----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Router---ASA--Local LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISP2 -----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this fashion you can configure load balancig of ISP and you can track the failure of ISP using IP SLA configuration in cisco routers.With the above setup only trusted traffic will be allowed in local lan which will be filtered by ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out the below link on PBR to implement in routers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a008009481d.shtml"&gt;http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a008009481d.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that clear out your query !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jan 2010 08:07:21 GMT</pubDate>
    <dc:creator>Ganesh Hariharan</dc:creator>
    <dc:date>2010-01-14T08:07:21Z</dc:date>
    <item>
      <title>Multiple WAN connections, one firewall?</title>
      <link>https://community.cisco.com/t5/network-security/multiple-wan-connections-one-firewall/m-p/1365476#M744855</link>
      <description>&lt;P&gt;I am not sure if this is possible, and if it is, I am then not sure how this would be accomplished:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will have 3 separate WAN connections provided by 3 separate ISP's coming into our office.&amp;nbsp; How may I set it up so that all three are firewalled using one ASA 5510?&amp;nbsp; I was told in passing that I could "just run them all through an edge router" then run that into the firewall, but upon further research, most routers are set to accept 1 WAN feed.&amp;nbsp; Is it possible to put a standard router outside of the firewall to combine the connections?&amp;nbsp; If so, what are the perils involved?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently have 2 WAN connections with a small Watchguard appliance on each.&amp;nbsp; It would be nice to have one firewall appliance (the ASA 5510) and one edge router appliance (re-commission one of the Watchguards or another small router) to handle the whole situation.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously I am not a network administrator, but rather the "computer guy"...so naturally I am expected to wave my standard-issue magic "computer guy" wand and make it happen...that or press the "Any" key.&amp;nbsp; So please forgive my lack of knowledge on the subject.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:57:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-wan-connections-one-firewall/m-p/1365476#M744855</guid>
      <dc:creator>steve.hassell</dc:creator>
      <dc:date>2019-03-11T16:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple WAN connections, one firewall?</title>
      <link>https://community.cisco.com/t5/network-security/multiple-wan-connections-one-firewall/m-p/1365477#M744856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the reason for 3 ISPs?&lt;/P&gt;&lt;P&gt;Redundancy or&lt;/P&gt;&lt;P&gt;Load balancing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Either way the ASA does not support this and you can read this thread there: &lt;/SPAN&gt;&lt;A class="jive-link-message-small" href="https://community.cisco.com/message/894921#894921"&gt;https://supportforums.cisco.com/message/894921&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use a router like you are thinking and do route tracking for redundance or PBR for load balancing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 18:31:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-wan-connections-one-firewall/m-p/1365477#M744856</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-01-13T18:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple WAN connections, one firewall?</title>
      <link>https://community.cisco.com/t5/network-security/multiple-wan-connections-one-firewall/m-p/1365478#M744857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will best if you terminate your ISP links in router and do a Policy based routing based on the incoming traffic from LAN.I would suggest you to make setup in the below manner&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISP1 -----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Router---ASA--Local LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISP2 -----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this fashion you can configure load balancig of ISP and you can track the failure of ISP using IP SLA configuration in cisco routers.With the above setup only trusted traffic will be allowed in local lan which will be filtered by ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out the below link on PBR to implement in routers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a008009481d.shtml"&gt;http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a008009481d.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that clear out your query !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jan 2010 08:07:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-wan-connections-one-firewall/m-p/1365478#M744857</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2010-01-14T08:07:21Z</dc:date>
    </item>
  </channel>
</rss>

