cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1019
Views
0
Helpful
1
Replies

ASA 5510 with two outside interfaces which is in separate ISPs

Fatouh3366
Level 1
Level 1

Hi All,

I have ASA5510 with PLUSE License.
I have 2 Inside interfaces as STAFF and MAIL
and two Outside interface OUT_STAFF and OUT_MAIL which is in separate ISP's.
now i want to nat STAFF to OUT_STAFF and MAIL to OUT_MAIL
because I'm having two default routes it gets impossible to do.
I know that it can solve this problem with context,i configured it but it didn't work
Can anyone help me to solve this problem.

1 Reply 1

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

Its pretty hard to give any specific answer to this with the starting information you gave.

Though I don't see a problem with configuring 2 Security Context and I'm not really sure what the problem was with trying that?

Beginning from the start you would

  • Boot the ASA in multiple context mode
  • Configure the 2 Security Contexts and attach 2 interfaces to both of them
    • "outside" interfaces would be connected to their own ISPs
    • "inside" interfaces would be connected to their own LANs
  • You would have to confirm that the LAN networks have a default route towards their own Security Context
    • If you have a L2 switch network behind the ASA then you simply take the needed Vlans to their own Security Context
    • If you have already router acting as the gateway for your local networks before the ASA I guess you would need to consider using Policy Based Routing to forward each LANs traffic to the correct Security Context.

- Jouni

Review Cisco Networking for a $25 gift card