<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two internet connection with ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130645#M895421</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello Kumaran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate all helpful posts and kindly mark them with a "check"/"Tick" so that other could refer that post and get some help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Oct 2008 11:51:14 GMT</pubDate>
    <dc:creator>abinjola</dc:creator>
    <dc:date>2008-10-08T11:51:14Z</dc:date>
    <item>
      <title>Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130638#M895410</link>
      <description>&lt;P&gt;I have two Broad Band internet conection and two lan network.One lan network is using the one internet Connection and another lan using second internet connection.Already I am using the ASA for one internet connection.I want to connect the second internet onnection to the Asa.Is it possible? if yes,Kinldy give the idea&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130638#M895410</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2019-03-11T13:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130639#M895413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2008 13:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130639#M895413</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-07T13:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130640#M895416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.But my case is diffrent,one lan network is using the first internet and another one should use the second internet through the ASA network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 09:12:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130640#M895416</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2008-10-08T09:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130641#M895417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - check out the below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/732/Tech/plicy_wp.htm" target="_blank"&gt;http://www.cisco.com/warp/public/732/Tech/plicy_wp.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 09:34:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130641#M895417</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-08T09:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130642#M895418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not using any cisco Router .Asa and service provider modem is in the nework&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 09:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130642#M895418</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2008-10-08T09:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130643#M895419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You require Policy Based Routing here, which ASA unfortunately is insufficient to do&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though I find this article here , see of this helps ........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say customer has above setup, with ISP1 being the Primary ISP and ISP2 being the Secondary ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming that you all know how ISP failback is configured and how it functions. To summarize, in ISP failback all traffic goes out&lt;/P&gt;&lt;P&gt;using ISP1 and if it fails, ASA/PIX starts routing traffic via ISP2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario I&lt;/P&gt;&lt;P&gt;==========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, customer does not want to configure ISP failback, but he needs to route Web (port 80,443) traffic via ISP2 and all other traffic&lt;/P&gt;&lt;P&gt;via ISP1. This requires PBR, which is not supported on ASA/PIX, but we can configure a workaround on ASA/PIX to make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following are the commands which will achieve it-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route ISP1 0 0 1.1.1.2 //Default route pointing to ISP1&lt;/P&gt;&lt;P&gt;route ISP2 0 0 2.2.2.2 2 //Default route with Metric 2 via ISP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (ISP2,inside) tcp 0.0.0.0 80 0.0.0.0 80&lt;/P&gt;&lt;P&gt;static (ISP2,inside) tcp 0.0.0.0 443 0.0.0.0 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (ISP1) 1 interface&lt;/P&gt;&lt;P&gt;global (ISP2) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats it !! Now all the traffic destined to any address on port 80/443 will be forcibly put on ISP2 interface and routed from there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: This stuff requires that we KNOW what the destination ports are, if there is some traffic which uses dynamic ports, like voice traffic we will have to route it via ISP1 and cannot make it route via ISP2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario II&lt;/P&gt;&lt;P&gt;===========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the same setup, if customer says that he wants half traffic to go via ISP1 and half traffic via ISP2, first you need to explain customer that ASA is NOT a load-balancer or packet-shaper. Hence we cannot *truly* achieve this, but we may configure ASA in such a manner that traffic for some destination IP address is routed via ISP1 and some is routed via ISP2. Following would be configuration commands in this scenario-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (ISP1) 1 interface&lt;/P&gt;&lt;P&gt;global (ISP2) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route ISP1 128.0.0.0 128.0.0.0 1.1.1.2&lt;/P&gt;&lt;P&gt;route ISP2 0.0.0.0 128.0.0.0 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first creates a default route that routes addresses with the first bit of 1 to 1.1.1.2 of ISP1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second creates a default route that routes addresses with the first bit of 0 to 2.2.2.2 of ISP2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: This will do traffic routing based on *Destination* IP addresses and NOT based on traffic load. As I mentioned, ASA is NOT a packet-shaper.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 11:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130643#M895419</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-10-08T11:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130644#M895420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very good info.I need to connect the internet connection physically int the ASA.Already one internet connection is connected in the ASA and working fine because of ur(abinjola &lt;/P&gt;&lt;P&gt;) help.So two interface already used.I have only one inteface now beacuse fourth interface(0/3) is not showing in the ASA(int 0,1,2 available).How will the connect the second internet connection)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 11:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130644#M895420</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2008-10-08T11:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130645#M895421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello Kumaran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate all helpful posts and kindly mark them with a "check"/"Tick" so that other could refer that post and get some help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 11:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130645#M895421</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-10-08T11:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130646#M895422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;J have done for proxy/mail server post(rating 5) which u have helped me lot. In the continuation I need to connect the internet connection physically in the ASA.(Proxy/mail server)Already one internet connection is connected in the ASA and working fine because of ur(abinjola ) help.So two interface already used.I have only one inteface now beacuse fourth interface(0/3) is not showing in the ASA(int 0,1,2 available).How will the connect the second internet connection).Pl reply back me&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Oct 2008 08:51:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130646#M895422</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2008-10-09T08:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130647#M895424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you only have 3 interfaces, and you have already used, then you need to "Trunk" and "VLAN" the outside connections on a switch.  You have have 1 physcial and many virtual interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some pointers to help you along:-&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/getting_started/asa5505/quick/guide/vlans.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/getting_started/asa5505/quick/guide/vlans.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/asdm52/user/guide/ifcs5505.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/asdm52/user/guide/ifcs5505.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Oct 2008 09:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130647#M895424</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-09T09:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130648#M895426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you have any physical Interface left on ASA to plug your 2ISP line there ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, then you need to create another Interface on ASA, this would be logical Interface (VLAN) &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Oct 2008 07:43:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130648#M895426</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-10-10T07:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130649#M895427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Possible solution:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA interfaces:&lt;/P&gt;&lt;P&gt;   ISP1 1.1.1.3&lt;/P&gt;&lt;P&gt;   ISP2 2.2.2.3&lt;/P&gt;&lt;P&gt;   VLAN1 192.168.1.10&lt;/P&gt;&lt;P&gt;   VLAN2 192.168.2.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP1 router: 1.1.1.1&lt;/P&gt;&lt;P&gt;ISP2 router: 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Target: VLAN1 goes out with ISP1 and VLAN2 with ISP2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT rules:&lt;/P&gt;&lt;P&gt;static (ISP1,VLAN1) 192.168.1.1 1.1.1.1&lt;/P&gt;&lt;P&gt;static (ISP2,VLAN2) 192.168.2.1 2.2.2.2&lt;/P&gt;&lt;P&gt;nat (VLAN1) 1 0 0 &lt;/P&gt;&lt;P&gt;nat (VLAN2) 2 0 0 &lt;/P&gt;&lt;P&gt;global (ISP1) 1 interface&lt;/P&gt;&lt;P&gt;global (ISP2) 2 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLAN1 gateway on hosts: 192.168.1.1&lt;/P&gt;&lt;P&gt;VLAN2 gateway on hosts: 192.168.2.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it work? I'll try it in a lab asap.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Nov 2008 17:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130649#M895427</guid>
      <dc:creator>Gian Paolo</dc:creator>
      <dc:date>2008-11-24T17:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Two internet connection with ASA</title>
      <link>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130650#M895428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;UPDATE:&lt;/P&gt;&lt;P&gt;I've tried it in a lab, it doesn't work.&lt;/P&gt;&lt;P&gt;Now I'll reconfigure the ASA in multi context mode, it seems the only solution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Dec 2008 08:06:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-internet-connection-with-asa/m-p/1130650#M895428</guid>
      <dc:creator>Gian Paolo</dc:creator>
      <dc:date>2008-12-02T08:06:30Z</dc:date>
    </item>
  </channel>
</rss>

