07-31-2019 12:16 PM
Here is my case. I currently have a Cisco ASA5545 running ASA 9.8(2) / ASDM 7.9(2)152. The firewall is up and running with several VPNs and internet access, etc. We just received a new 1GB internet circuit which we want to test for a while before cutting over.
--------------------------
For reference;
G0/0 - Outside
G0/1 - Inside
G0/6 - ATT_Inside_Test
G0/7 - 1GB_ATT_TEST
--------------------------
I used ports G0/6 for my "test" internal network (192.168.69.0/24) and configured G0/7 for my new 1GB circuit. Now there is a default route already set that forwards traffic out the original internet port (G0/0 named Outside).
How can I set this up so that only users on the new test network of 192.168.69.0 network with go out the new (G0/7) 1GB interface for internet access while all other users continue to use the original G0/0 interface?
I did try to set this up for some testing but it appears not matter what I do or try even the traffic on the 192.168.69.0 net still wants to go out the "Outside" interface (G0/0) and not the new 1GB Interface (G0/7).
Is what I'm asking for even possible? Obviously this is a production firewall so I am very limited on drastic configuration change options.
Here is one example.
| 6 | Jul 31 2019 | 15:12:09 | 302015 | 192.168.69.69 | 65261 | 66.109.38.250 | 53 | Built outbound UDP connection 175781294 for Outside:66.109.38.250/53 (66.109.38.250/53) to ATT_Inside_TEST:192.168.69.69/65261 (192.168.69.69/65261)
|
Solved! Go to Solution.
07-31-2019 12:48 PM
yes if you want to route only source based then PBR is the option you have and best option to test.
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
07-31-2019 12:23 PM
is the new igb have different IP range ? or you going to use same IP address ?
you can do with PBR for that specific range to route to new G0/7
here is example :
https://www.networkstraining.com/cisco-asa-policy-based-routing-pbr/
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
07-31-2019 12:25 PM
Different IP completely. Original one starts with 216.x.x.x while the other starts with 12.x.x.x
07-31-2019 12:26 PM
Is policy based routing really the only option? I did see that but was hoping there was an "easier" solution :-)
07-31-2019 12:48 PM
yes if you want to route only source based then PBR is the option you have and best option to test.
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide