<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA default route with tracking in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615036#M922550</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for updating the community.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Jan 2011 15:33:00 GMT</pubDate>
    <dc:creator>Panos Kampanakis</dc:creator>
    <dc:date>2011-01-18T15:33:00Z</dc:date>
    <item>
      <title>ASA default route with tracking</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615030#M922543</link>
      <description>&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;I'm working with a VPN link as a backup&amp;nbsp; scenario in my lab. (See &lt;A href="https://community.cisco.com/message/3246029#3246029" target="_blank"&gt;here &lt;/A&gt;for details.)&amp;nbsp; I've got just about everything working.&amp;nbsp; When the main link&amp;nbsp; drops, the traffic reroutes to the VPN over the ASA and everything&amp;nbsp; works great.&amp;nbsp; The one last issue I'm having now is that I can't access&amp;nbsp; the ASA directly from the HQ side. I need to be able to access these&amp;nbsp; devices once they are in the field. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; believe this is due to the default route being the outside interface.&amp;nbsp;&amp;nbsp; When the main link is up and working, the traffic would have to route to the&amp;nbsp; inside interface instead of the outside.&amp;nbsp; As such, I'm trying to set up a&amp;nbsp; default route with a monitor.&amp;nbsp; The IP address I'm monitoring would only&amp;nbsp; be accessible when the main link is up, via the inside interface&amp;nbsp; (10.99.0.101 in the diagram above).&amp;nbsp; When I try to add the monitored&amp;nbsp; default route, I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(config)# route inside 0 0 10.107.0.1 track 101&lt;BR /&gt;ERROR: Cannot add route entry, conflict with existing routes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According&amp;nbsp; to the documentation, this should be doable.&amp;nbsp; I should be able to have&amp;nbsp; up to three default routes.&amp;nbsp; The only other default route is out the&amp;nbsp; outside interface and is obtained via DHCP.&amp;nbsp; A show route reveals:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 24.53.128.0 255.255.224.0 is directly connected, outside&lt;BR /&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.107.0.0 255.255.0.0 [1/0] via 10.107.0.1, inside&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.107.0.0 255.255.255.0 is directly connected, inside&lt;BR /&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.99.0.0 255.255.255.0 [1/0] via 10.107.0.1, inside&lt;BR /&gt;d*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 24.53.128.1, outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I get this set up so that the default route is inside when 10.99.0.101 is available and outside when it is not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(ASA 5505 v8.3(2))&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:13:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615030#M922543</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2020-02-21T12:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route with tracking</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615031#M922545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look attached link, you can try add route accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml"&gt;http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 03:27:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615031#M922545</guid>
      <dc:creator>cheungwaitim</dc:creator>
      <dc:date>2011-01-14T03:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route with tracking</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615032#M922546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have access to that link.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 13:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615032#M922546</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2011-01-14T13:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route with tracking</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615033#M922547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is interesting.&lt;/P&gt;&lt;P&gt;If you track an outside ip address it all works right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you open a case for this, we might need to fix it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 19:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615033#M922547</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2011-01-14T19:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route with tracking</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615034#M922548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't tried tracking an outside ip address.&amp;nbsp; I don't even set the default route in the config - it is set to obtain it from the DCHP server on the outside interface. I suppose I could try it on the outside interface as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The track commands themselves work fine as far as defining the ip to track, etc.&amp;nbsp; I can see the connections being made for the pings to the ip address.&amp;nbsp; It's just when I try to add the route that it fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will probably not have time to mess with this until Monday.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 21:11:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615034#M922548</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2011-01-14T21:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route with tracking</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615035#M922549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In trying to add a tracked route to the outside, it worked.&amp;nbsp; By default, the metric is 128 when you add it like that.&amp;nbsp; That got me to thinking - I was trying to add it with a metric of 1, so I checked the DCHP settings, and it was also set to a metric of 1.&amp;nbsp; So, even though the documentation says you can have up to three default routes, apparently the key is that they can not have the same metric.&amp;nbsp; Once I changed the metric of the DHCP default route to 10, I was able to add the inside default route with tracking at a metric of 1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jan 2011 15:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615035#M922549</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2011-01-18T15:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route with tracking</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615036#M922550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for updating the community.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jan 2011 15:33:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-with-tracking/m-p/1615036#M922550</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2011-01-18T15:33:00Z</dc:date>
    </item>
  </channel>
</rss>

