cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
513
Views
0
Helpful
1
Replies

ASA 5520 with 2 ISP

ochalmers
Level 1
Level 1

Hi Guys, i'm trying to configure an ASA with two ISP to be reached from internet for vpn access, the objective is that the user can use any of the Public address attached to ASA to connect to the company. Is this possible? i'm facing some problems because i can not use two different default routes (same AD) pointing to two different interfaces, this is the message that i receive "ERROR: Cannot add route entry, possible conflict with existing routes" and when i change the AD of one of the default routes i just can reach one ISP.

Could you please point me to right direction!!!

Any Ideas!!!

Thanks.

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello,

The error you are getting is due to the fact that what you are doing is not possible on the ASA, you cannot have 2 default routes on the ASA.

So if you are looking for is due to redundancy purposes the feature you are looking to implement is called SLA ( Service Level Agreegment)

This will allow you to use one ISP but if by any chances the primary link goes down, inmidiatly the secondary link will start working with almost no down-time.

This feature is also available on routers so you may have heard of it.

Anyway here is the ASA configuration link for this feature.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

Do rate all the helpful posts.

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking for a $25 gift card