<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multi-homed internet connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391948#M830510</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the third Internet connection terminates on the same router, or it has seperate router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am assuming the default GW for the ISA is the Active pix and the Pix points to one of the routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Security Appliance doesnt support PBR , and would therfore PBR has to be implemented on the router terminates both connections and uses the ADSl connection for the critical application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Jan 2010 13:57:54 GMT</pubDate>
    <dc:creator>Mohamed Sobair</dc:creator>
    <dc:date>2010-01-19T13:57:54Z</dc:date>
    <item>
      <title>Multi-homed internet connection</title>
      <link>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391947#M830491</link>
      <description>&lt;P&gt;I have the following components, ISA Server, two standalone PIX firewalls, two internet routers (800 series)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently only one router is being used for internet access.&lt;/P&gt;&lt;P&gt;We now have a second internet DSL connection and want to use one connection for exclusive use of buisiness critical applications, the other connection will be used for general internet browsing. The "problem" is that all clients use the ISA server as gateway. Normally I would implement something like a route-map to set the next-hop...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance for any feedback&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391947#M830491</guid>
      <dc:creator>vergeerf</dc:creator>
      <dc:date>2019-03-11T16:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-homed internet connection</title>
      <link>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391948#M830510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the third Internet connection terminates on the same router, or it has seperate router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am assuming the default GW for the ISA is the Active pix and the Pix points to one of the routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Security Appliance doesnt support PBR , and would therfore PBR has to be implemented on the router terminates both connections and uses the ADSl connection for the critical application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2010 13:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391948#M830510</guid>
      <dc:creator>Mohamed Sobair</dc:creator>
      <dc:date>2010-01-19T13:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-homed internet connection</title>
      <link>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391949#M830539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I see that you need to use ONE ( DSL ) internet line for normal internet surfing (port 80 traffic) and another line for business critical applications.&lt;/P&gt;&lt;P&gt;First of all,&amp;nbsp; I would like to inform you thatyou can not use your second ISP&amp;nbsp; ALONG with your primary ISP as Cisco ASA cannot do Policy Based Routing. Please check :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a00805b87d8.shtml#pbr"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a00805b87d8.shtml#pbr&lt;/A&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, since you need to send a FIXED port traffic to one circuit , we have a workaround developed for such cases :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (outside_1) 1 interface&lt;/P&gt;&lt;P&gt;global (outside_2) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside_2) tcp 0.0.0.0 www 0.0.0.0 netmask 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside_1&amp;nbsp; 0 0 x.x.x.x //next hop router's IP address for ISP_1//&lt;/P&gt;&lt;P&gt;route outside_2 0 0 y.y.y.y&amp;nbsp; 2 //next hop router's IP address for ISP_2 with an administrative Distance of 2 (higher than primary route)//&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vijaya&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2010 14:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391949#M830539</guid>
      <dc:creator>vilaxmi</dc:creator>
      <dc:date>2010-01-19T14:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-homed internet connection</title>
      <link>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391950#M830581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;Does the third Internet connection terminates on the same router, or it has seperate router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a seperate router (actually the second internet connection) no the third.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's good to know that PBR is not supported on the PIX / ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Jan 2010 10:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391950#M830581</guid>
      <dc:creator>vergeerf</dc:creator>
      <dc:date>2010-01-23T10:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-homed internet connection</title>
      <link>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391951#M830613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your input, I will try to setup of test environment before implementing this in production &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It's good to know that PBR is not supported on the PIX / ASA. Because I was thinking in this direction.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Jan 2010 10:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-homed-internet-connection/m-p/1391951#M830613</guid>
      <dc:creator>vergeerf</dc:creator>
      <dc:date>2010-01-23T10:20:51Z</dc:date>
    </item>
  </channel>
</rss>

