07-23-2010 02:29 AM - edited 03-11-2019 11:15 AM
Hello!
I am supporting a customer who has an ASA 5510 (8.04) connected to two ISPs. He wants to use one ISP for internet access, and the other ISP to publish several servers from the DMZ with NAT. So, basically splitting the traffic, all internet access going through one ISP and DMZ access for individual servers through the other. As I understand it, this cannot be done with the ASA, because it would require PBR which the ASA cannot do. Am I correct or does anyone have a solution to offer?
Thanks and regards,
Meg Rainbow
07-23-2010 02:36 AM
You are absolutely correct. ASA does not support PBR, and also does not support 2 active default gateways through 2 different interfaces.
If the DMZ server through the second ISP is only going to a particular destination, then you can configure a static route for that particular destination, and you will be able to use the second ISP. However, if you require default gateway as well for the second ISP, then it is not supported on the ASA unfortunately.
Hope that answers your question.
07-23-2010 06:37 AM
Thanks for your quick reply!
Regards,
Meg Rainbow
07-23-2010 08:20 AM
Great, pls mark the question as answered. Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide