cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
997
Views
0
Helpful
2
Replies

CISCO ASA 5510 source basing routing

Dmitriy Popov
Level 1
Level 1

Hi, all!

several organizations wants to place their equipment and servers in my datacenter. They want to use the same resource - 10.3.1.5. I want to connect their servers and VPN-gates via my CISCO ASA 5510. When the organization was the only on ASA was static route "10.3.1.5 via 10.200.1.2". But now this decision doesnt work. Organization1 need to go to 10.3.1.5 via VPN-gate 10.200.1.2. Organization2 need to go to 10.3.1.5 via 10.200.2.2. I cannot connect teir servers and VPN-gates directly. I should do it via ASA 5510.

I need some thing like IOS PBR (more precisely - routing based on source address). Could you advice me how I can configure scheme in attachement on my ASA? May be it will be a kind of NAT?

Note: Also I need to give access to VPN-gates from other networks (NET 1 - NET n)

2 Replies 2

julomban
Level 3
Level 3

Hello Dmitriy,

I am afraid that is not possible what you are trying to accomplish with your ASA. The ASA only routes traffic based on destination IP (10.3.1.5) not by source (Organization1 and Organization2).

This is only possible on Cisco Routers.

Regards,

Juan Lombana

Please rate helpful posts.

Andrew Phirsov
Level 7
Level 7

If possible, you can translate 10.3.1.5 on each VPN-gate to something unique for corresponding organization when going to ASA (using some kind of static nat). For example, on VPN gate1 you can translate 10.3.1.5 to 10.31.1.5 and to VPN gate2 - to 10.32.1.5. On ASA u'll just add two static routes each pointing to corresponding VPN-gate.

route to 10.31.1.5 via 10.200.1.2

route to 10.32.1.5 via 10.200.2.2

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card