<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISP Migration - Two ISP's, one ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398906#M837459</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jiveTT-hover-user&amp;nbsp; jive-username-link" href="https://community.cisco.com/people/mlinsemier" id="jive-28856230,920,097,146,585,038" onmouseout="" onmouseover=""&gt;mlinsemier&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What did you finally do to resolve your ISP Migration?&amp;nbsp; I've have a very similar setup as you did and my customer has several vendors in their DMZ requiring acceptance testing on the new ISP prior to any final cut-over.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Jul 2010 17:30:00 GMT</pubDate>
    <dc:creator>Barry Beitz</dc:creator>
    <dc:date>2010-07-28T17:30:00Z</dc:date>
    <item>
      <title>ISP Migration - Two ISP's, one ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398901#M837450</link>
      <description>&lt;P&gt;We are currently in the process of switching ISP's from one to another.&amp;nbsp; I was hoping that I could, with the Cisco ASA 5510, run both ISP's in tandem without having to do a "hard cutover" of changing IP's of all public facing devices on a weekend.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both of the ISP's terminate into the same router (one is NxT1 and the other is Ethernet).&amp;nbsp; Initially, I created a secondary IP subnet (for the new block) on the same interface that the existing public subnet is on. Then I planned on setting up PBR on the external ISP terminating router to make sure that the traffic is routed correctly based on what was presented to it.&amp;nbsp; I haven't got this to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In theory will this even work?&amp;nbsp; I would like to look at changing the PAT address to the new ISP (it's faster) and then start migrating the other devices at my pace.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone has any input, please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398901#M837450</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2019-03-11T16:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Migration - Two ISP's, one ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398902#M837452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;mlinsemier wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently in the process of switching ISP's from one to another.&amp;nbsp; I was hoping that I could, with the Cisco ASA 5510, run both ISP's in tandem without having to do a "hard cutover" of changing IP's of all public facing devices on a weekend.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both of the ISP's terminate into the same router (one is NxT1 and the other is Ethernet).&amp;nbsp; Initially, I created a secondary IP subnet (for the new block) on the same interface that the existing public subnet is on. Then I planned on setting up PBR on the external ISP terminating router to make sure that the traffic is routed correctly based on what was presented to it.&amp;nbsp; I haven't got this to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In theory will this even work?&amp;nbsp; I would like to look at changing the PAT address to the new ISP (it's faster) and then start migrating the other devices at my pace.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone has any input, please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt; Initially, I created a secondary IP subnet (for the new block) on the same interface that the existing public subnet is on&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what you mean here. Do you mean on the ASA because as far as i was aware the ASA doesn't support secondary addressing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have an ASA connected to a router which has 2 ISP terminations. Are you aware that you do not need to actually have an address on an interface to use it as a PAT address on the ASA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps a quick topology diagram with addressing would help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jan 2010 22:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398902#M837452</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-01-05T22:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Migration - Two ISP's, one ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398903#M837454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe I should take a step back. Our current topology is two ASA 5510's (in failover mode) connected to Dirty DMZ switch which connects to a Cisco 3825 connected to UUNet via 4xT1. We&amp;nbsp; also have a DMZ where our public facing servers are in.&amp;nbsp; So it looks like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Private Network ----&amp;gt; ASA ---&amp;gt; Dirty DMZ Switch ---&amp;gt; 3825 Router ---&amp;gt; UUNet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of our public addressable IP&amp;nbsp; addresses hang off devices in the DMZ.&amp;nbsp; A few are also NATed to the inside network (ACS, Syslog, etc.).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We just signed for a 20Mbps contact with ACC (AT&amp;amp;T) handed off to us via Ethernet.&amp;nbsp; Along with this there is a new /26 subnet block for public IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like to do is connect both ISP's to the ASA's, initially move over all of the PAT traffic (our corporate users) to the new 20Mbps link, and then move over the remaining publicly addressed servers and appliances as time provides.&amp;nbsp; From what I understand this would require me to be able to NAT to two different subnets.&amp;nbsp; My worry is that if there is a default route to our existing provider, that when I add the new address for the PAT of the new provider I would need to change this default route, in effect breaking all of the public NATed devices (as traffic would come in and leave on a different provider).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can terminate the new AT&amp;amp;T link on the existing router (via Ethernet), terminate it directly to a spare interface on the ASA, or connect it to a secondary router (I have spares), but I'm trying to see what the best way is to handle this.&amp;nbsp; We currently do have IP addresses bound to ASA external interface but could change this if necessary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any input or ideas would be greatly apprecaited.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jan 2010 19:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398903#M837454</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2010-01-06T19:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Migration - Two ISP's, one ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398904#M837456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi matt,&lt;/P&gt;&lt;P&gt;I am assuming you have this kind of network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Terminating two ISPs on ASA/PIX-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISP1------------------Internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.2&lt;SPAN&gt; &lt;/SPAN&gt;&amp;nbsp; |&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;SPAN&gt; &lt;/SPAN&gt;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | &lt;SPAN&gt; &lt;/SPAN&gt;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;SPAN&gt; &lt;/SPAN&gt;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.1&lt;SPAN&gt; &lt;/SPAN&gt;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PIX/ASA|2.2.2.1----2.2.2.2|ISP2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.3.3.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Internal Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to configure half traffic through the ISP1 and half traffic through ISP2, Here i would like to say that ASA is NOT a load-balancer or packet-shaper. Hence we cannot&amp;nbsp; *truly* achieve this, but we may configure ASA in such a manner that traffic for some destination IP address is routed via ISP1 and some is routed via ISP2. Following would be configuration commands in this scenario-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (ISP1) 1 interface&lt;/P&gt;&lt;P&gt;global (ISP2) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route ISP1 128.0.0.0 128.0.0.0 1.1.1.2 &lt;/P&gt;&lt;P&gt;route ISP2 0.0.0.0 128.0.0.0 2.2.2.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first creates a default route that routes addresses with the first&amp;nbsp; bit of 1 to 1.1.1.2 of ISP1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second creates a default route that routes addresses with the first bit of 0 to 2.2.2.2 of ISP2.&lt;/P&gt;&lt;P&gt;Note: This will do traffic routing based on *Destination* IP addresses and NOT based on traffic load. As I mentioned, ASA is NOT a packet-shaper.&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jan 2010 20:56:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398904#M837456</guid>
      <dc:creator>abhadana</dc:creator>
      <dc:date>2010-01-06T20:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Migration - Two ISP's, one ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398905#M837457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not interested really in load balancing or packet shaping at this time.&amp;nbsp; The only thing I want to accomplish is to route my Internal private network traffic (users, proxies, etc) over the new ISP2 link and leave all of the other traffic (my DMZ servers) exiting out ISP1.&amp;nbsp; Eventually, as I move public facing servers (one at a time) from ISP1 to ISP2 they will go their respective routes, then eventually I will terminate ISP1 once all of the servers are moved over.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However here is the question.&amp;nbsp; ISP2 gives me two IP addresses, our CPE address and their WAN gateway.&amp;nbsp; They give us an ADDITIONAL subnet which is the publicly routed network, but it's on a different subnet.&amp;nbsp; Will I need a router off the the ASA interface so that it will look like the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA (12.x.x.129/26) ---- (12.x.x.130/26 - G0/0) OUR ROUTER (G0/1 - 12.248.x.86) ----- (12.248.x.85) ISP2 GATEWAY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I apply the 12.248.x.86 to the ASA Interface for ISP2, set the route to 12.248.x.85, can I still NAT the 12.x.x.128/26 publicly routed IP's off of that interface without putting a router in between?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Does this make sense?&amp;nbsp; Thanks for all your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jan 2010 21:56:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398905#M837457</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2010-01-06T21:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Migration - Two ISP's, one ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398906#M837459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jiveTT-hover-user&amp;nbsp; jive-username-link" href="https://community.cisco.com/people/mlinsemier" id="jive-28856230,920,097,146,585,038" onmouseout="" onmouseover=""&gt;mlinsemier&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What did you finally do to resolve your ISP Migration?&amp;nbsp; I've have a very similar setup as you did and my customer has several vendors in their DMZ requiring acceptance testing on the new ISP prior to any final cut-over.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jul 2010 17:30:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398906#M837459</guid>
      <dc:creator>Barry Beitz</dc:creator>
      <dc:date>2010-07-28T17:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Migration - Two ISP's, one ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398907#M837461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hi Matt,&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Question for you...&amp;nbsp;&amp;nbsp; how big is your current static nat configuration for your public servers?&amp;nbsp; I have been in your scenario two times, and found out that it is much easier to do a hot cutover than gradual cutover ( more headaches ) , if you are indeed actually decomisioning the old ISP&amp;nbsp; a hot cutover is recommended way much easier , unless your situation with asa static translation&amp;nbsp; holds hundreds of static translations I can see the justification for gradual cutover but I don't think this could be your case as&amp;nbsp; from what you indicated your new ISP is providing /26 so we are not talking about over&amp;nbsp; 60 public usable&amp;nbsp; addresses, so the hotcut should be fairly&amp;nbsp; simple and at the same time be able to fall back if issues by placing back old firewallconfig , you will prepare few things,&amp;nbsp; obiously fully backup your config&amp;nbsp; in clear text as well as via tftp prior migration,&amp;nbsp; create a sctrip in notepad&amp;nbsp; for&amp;nbsp; the removal of old nat translation&amp;nbsp; and creation new&amp;nbsp; ones ,&amp;nbsp; global nat pools , your outside interface re-IP, new default route&amp;nbsp; , your inbound&amp;nbsp; access-list reflecting new public IPs ,&amp;nbsp; after you configure this in firewall ,&amp;nbsp; shutdown the old ISP multylink interface if that is what you have , clear xlate in your firewall, and clear internet router's arp catch ,&amp;nbsp; this process should not take you more than one hour two hours tops...&amp;nbsp; prior hotcut over&amp;nbsp; have handy your new ISP NOC to be able to troubleshoot any issues, but from experience it should be fairly easy going hotcut migration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;my 2 cents&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 06:20:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/isp-migration-two-isp-s-one-asa-5510/m-p/1398907#M837461</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2010-07-29T06:20:01Z</dc:date>
    </item>
  </channel>
</rss>

