cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
542
Views
0
Helpful
1
Replies

Asa 5510- 2 IP's outbound Failover with RTR, Inbound possible?

dmooreami
Level 3
Level 3

I know I can use the RTR statement to determine when the primary ISP circuit goes down via this technote:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

My question can I assign static Nats on the backup ISP connection to the same inside servers in the dmz.?

Example 10.1.1.11 is mapped to ISP1 ExternaIP of 65.217.77.11. Can it 10.1.1.11 also be mapped to ISP2's 208.217.77.11?

This way I can get my DNS changed and my inbound traffic to servers in my DMZ on the asa 5510 running 8.0.3 code can continue to receive Inbound traffic.

Thanks

1 Reply 1

JohnTylerPearce
Level 7
Level 7

I don't think you can on the same ASA, but who knows if there is some sort of trick to get around that. I would think that if you had a static mapping of 10.1.1.11 to 65.217.77.11, since it's static it will always have an active translation in the XLATE table. So, if this is all on the same ASA, I don't know how the ASA would be able to tell the difference.

Review Cisco Networking for a $25 gift card