<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 Multiple ISP routing problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-multiple-isp-routing-problem/m-p/3736969#M9140</link>
    <description>&lt;P&gt;are you doing a no-NAT from the internal interface TO the DMZ interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in otherwords, add a NAT statement to NOT nat from int. to external.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Nov 2018 02:09:20 GMT</pubDate>
    <dc:creator>Dennis Mink</dc:creator>
    <dc:date>2018-11-01T02:09:20Z</dc:date>
    <item>
      <title>ASA 5510 Multiple ISP routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-multiple-isp-routing-problem/m-p/3736921#M9139</link>
      <description>&lt;P&gt;We have an ASA 5510 with dual ISP. The default route is configured to ISP1, and the inside clients are goes also to ISP1. We have a DMZ interface, there are public servers in it with private IP, the interesting ports are forwarded to them. The public services - hosted by the servers in the DMZ - are reachable from the ISP2's public IPs.&lt;/P&gt;
&lt;P&gt;The problem is, that the clients from the inside network can't reach the services in the DMZ with public IP. Logically the traffic should goes like Client -&amp;gt; ASA inside -&amp;gt; ASA outside1 -&amp;gt; ISP1 -&amp;gt; ISP2 -&amp;gt; ASA outside interface 2 -&amp;gt; DMZ. Ok, but the ASA has connected interface to the ISP2's IP range, so maybe the traffic shouldn't go through the ISPs, the ASA should route it from the client to the DMZ server. Should we have NAT rule from the client network directly to the DMZ? The log says that failed to locate egress interface.&lt;/P&gt;
&lt;P&gt;Do you have any ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-multiple-isp-routing-problem/m-p/3736921#M9139</guid>
      <dc:creator>Attila Erdos</dc:creator>
      <dc:date>2020-02-21T16:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Multiple ISP routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-multiple-isp-routing-problem/m-p/3736969#M9140</link>
      <description>&lt;P&gt;are you doing a no-NAT from the internal interface TO the DMZ interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in otherwords, add a NAT statement to NOT nat from int. to external.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 02:09:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-multiple-isp-routing-problem/m-p/3736969#M9140</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-11-01T02:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Multiple ISP routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-multiple-isp-routing-problem/m-p/3738541#M9141</link>
      <description>&lt;P&gt;You could try nat reflection on the ASA to access DMZ servers public IPs directly from the LAN.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Azam&lt;/P&gt;</description>
      <pubDate>Sat, 03 Nov 2018 20:05:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-multiple-isp-routing-problem/m-p/3738541#M9141</guid>
      <dc:creator>mkazam001</dc:creator>
      <dc:date>2018-11-03T20:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Multiple ISP routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-multiple-isp-routing-problem/m-p/3742893#M9142</link>
      <description>&lt;P&gt;You're right! It was a basic problem, the NAT statement was the problem. Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 14:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-multiple-isp-routing-problem/m-p/3742893#M9142</guid>
      <dc:creator>Attila Erdos</dc:creator>
      <dc:date>2018-11-09T14:32:34Z</dc:date>
    </item>
  </channel>
</rss>

