<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple networks for outside connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248325#M778628</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the networks will be reachable from the internet if the routes are separated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Nov 2009 21:51:51 GMT</pubDate>
    <dc:creator>mkharban</dc:creator>
    <dc:date>2009-11-03T21:51:51Z</dc:date>
    <item>
      <title>Multiple networks for outside connection</title>
      <link>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248322#M778623</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to configure 2 networks for outside connection so that I can assign diffirent IP's to the inside hosts.&lt;/P&gt;&lt;P&gt;The interface configuration is as following,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.1&lt;/P&gt;&lt;P&gt; vlan 10&lt;/P&gt;&lt;P&gt; nameif outside1&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address x.x.x.2 255.255.255.192&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.2&lt;/P&gt;&lt;P&gt; vlan 20&lt;/P&gt;&lt;P&gt; nameif outside2&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address y.y.y.2 255.255.255.224&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.16.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I added either&lt;/P&gt;&lt;P&gt;route outside1 0.0.0.0 0.0.0.0 x.x.x.1 1&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;route outside1 0.0.0.0 0.0.0.0 y.y.y.1 1&lt;/P&gt;&lt;P&gt;x.x.x.2 on outside1 is reachable from Internet but y.y.y.2 on outside2 is not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to add&lt;/P&gt;&lt;P&gt;route outside2 0.0.0.0 0.0.0.0 y.y.y.1 1&lt;/P&gt;&lt;P&gt;But ASA doesn't allow me to do it---&lt;/P&gt;&lt;P&gt;ERROR: Cannot add route entry, conflict with existing routes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone kindly advise how to achieve it? TIA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:35:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248322#M778623</guid>
      <dc:creator>David Lin</dc:creator>
      <dc:date>2019-03-11T16:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple networks for outside connection</title>
      <link>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248323#M778624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two ways of doing it. Below given are both the methods:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Terminating two ISPs on ASA/PIX-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP1------------------Internet&lt;/P&gt;&lt;P&gt;1.1.1.2 | &lt;/P&gt;&lt;P&gt;| |&lt;/P&gt;&lt;P&gt;| |&lt;/P&gt;&lt;P&gt;| |&lt;/P&gt;&lt;P&gt;1.1.1.1 |&lt;/P&gt;&lt;P&gt;PIX/ASA|2.2.2.1----2.2.2.2|ISP2&lt;/P&gt;&lt;P&gt;3.3.3.1&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;|&lt;/P&gt;&lt;P&gt;Internal Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say we has above setup, with ISP1 being the Primary ISP&lt;/P&gt;&lt;P&gt;and ISP2 being the Secondary ISP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming that you all know how ISP failback is configured and&lt;/P&gt;&lt;P&gt;how it functions. To summarize, in ISP failback all traffic goes out&lt;/P&gt;&lt;P&gt;using ISP1 and if it fails, ASA/PIX starts routing traffic via ISP2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario I&lt;/P&gt;&lt;P&gt;==========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, we do not want to configure ISP failback, but we needs &lt;/P&gt;&lt;P&gt;to route Web (port 80,443) traffic via ISP2 and all other traffic &lt;/P&gt;&lt;P&gt;via ISP1. This requires PBR, which is not supported on ASA/PIX, but&lt;/P&gt;&lt;P&gt;we can configure a workaround on ASA/PIX to make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following are the commands which will achieve it-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route ISP1 0 0 1.1.1.2    //Default route pointing to ISP1&lt;/P&gt;&lt;P&gt;route ISP2 0 0 2.2.2.2 2 //Default route with Metric 2 via ISP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (ISP2,inside) tcp 0.0.0.0 80 0.0.0.0 80&lt;/P&gt;&lt;P&gt;static (ISP2,inside) tcp 0.0.0.0 443 0.0.0.0 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (ISP1) 1 interface&lt;/P&gt;&lt;P&gt;global (ISP2) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats it !! Now all the traffic destined to any address on port 80/443&lt;/P&gt;&lt;P&gt;will be forcibly put on ISP2 interface and routed from there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: This stuff requires that we KNOW what the destination ports are, &lt;/P&gt;&lt;P&gt;if there is some traffic which uses dynamic ports, like voice traffic&lt;/P&gt;&lt;P&gt;we will have to route it via ISP1 and cannot make it route via ISP2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario II&lt;/P&gt;&lt;P&gt;===========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the same setup, if we say that we wants half traffic to go&lt;/P&gt;&lt;P&gt;via ISP1 and half traffic via ISP2, first we need to understand&lt;/P&gt;&lt;P&gt;that ASA is NOT a load-balancer or packet-shaper. Hence we cannot &lt;/P&gt;&lt;P&gt;*truly* achieve this, but we may configure ASA in such a manner that&lt;/P&gt;&lt;P&gt;traffic for some destination IP address is routed via ISP1 and some&lt;/P&gt;&lt;P&gt;is routed via ISP2. Following would be configuration commands in this&lt;/P&gt;&lt;P&gt;scenario-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (ISP1) 1 interface&lt;/P&gt;&lt;P&gt;global (ISP2) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route ISP1 128.0.0.0 128.0.0.0 1.1.1.2 &lt;/P&gt;&lt;P&gt;route ISP2 0.0.0.0 128.0.0.0 2.2.2.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first creates a default route that routes addresses with the first &lt;/P&gt;&lt;P&gt;bit of 1 to 1.1.1.2 of ISP1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second creates a default route that routes addresses with the first &lt;/P&gt;&lt;P&gt;bit of 0 to 2.2.2.2 of ISP2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: This will do traffic routing based on *Destination* IP addresses and&lt;/P&gt;&lt;P&gt;NOT based on traffic load. As I mentioned, ASA is NOT a packet-shaper.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Nov 2009 18:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248323#M778624</guid>
      <dc:creator>mkharban</dc:creator>
      <dc:date>2009-11-03T18:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple networks for outside connection</title>
      <link>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248324#M778626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your so detail explaination!&lt;/P&gt;&lt;P&gt;I tested method I and it worked fine. But some applications request dynamic detination port in both two networks, so I can use this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding to the second solution, can both 2 networks be fully reachable from Internet if I sperate the route?&lt;/P&gt;&lt;P&gt;Thank you so much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Nov 2009 21:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248324#M778626</guid>
      <dc:creator>David Lin</dc:creator>
      <dc:date>2009-11-03T21:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple networks for outside connection</title>
      <link>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248325#M778628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the networks will be reachable from the internet if the routes are separated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Nov 2009 21:51:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248325#M778628</guid>
      <dc:creator>mkharban</dc:creator>
      <dc:date>2009-11-03T21:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple networks for outside connection</title>
      <link>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248326#M778630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But I'm having difficulty to ping ISP2 from ISP1 network or vice versa.&lt;/P&gt;&lt;P&gt;I tried to ping them from ISP3, it's same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.1&lt;/P&gt;&lt;P&gt; vlan 10&lt;/P&gt;&lt;P&gt; nameif ISP1&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 1.1.1.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.2&lt;/P&gt;&lt;P&gt; vlan 20&lt;/P&gt;&lt;P&gt; nameif ISP2&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 2.2.2.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.16.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route ISP1 0.0.0.0 0.0.0.0 1.1.1.1 1&lt;/P&gt;&lt;P&gt;route ISP2 128.0.0.0 255.0.0.0 1.1.1.2 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Nov 2009 18:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-networks-for-outside-connection/m-p/1248326#M778630</guid>
      <dc:creator>David Lin</dc:creator>
      <dc:date>2009-11-04T18:57:54Z</dc:date>
    </item>
  </channel>
</rss>

