cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
948
Views
5
Helpful
4
Replies

ASA5545 with two diffrent ISPs

rickcorriveau
Level 1
Level 1

Here is my case.   I currently have a Cisco ASA5545 running ASA 9.8(2) / ASDM 7.9(2)152.  The firewall is up and running with several VPNs and internet access, etc.  We just received a new 1GB internet circuit which we want to test for a while before cutting over.  

--------------------------

For reference;

G0/0 - Outside

G0/1 - Inside

G0/6 - ATT_Inside_Test

G0/7 - 1GB_ATT_TEST

--------------------------

I used ports G0/6 for my "test" internal network (192.168.69.0/24) and configured G0/7 for my new 1GB circuit.   Now there is a default route already set that forwards traffic out the original internet port (G0/0 named Outside).   

 

How can I set this up so that only users on the new test network of 192.168.69.0 network with go out the new (G0/7) 1GB interface for internet access while all other users continue to use the original G0/0 interface?

 

I did try to set this up for some testing but it appears not matter what I do or try even the traffic on the 192.168.69.0 net still wants to go out the "Outside" interface (G0/0) and not the new 1GB Interface (G0/7).

 

Is what I'm asking for even possible?  Obviously this is a production firewall so I am very limited on drastic configuration change options.

 

Here is one example.

6Jul 31 201915:12:09302015192.168.69.696526166.109.38.25053

Built outbound UDP connection 175781294 for Outside:66.109.38.250/53 (66.109.38.250/53) to ATT_Inside_TEST:192.168.69.69/65261 (192.168.69.69/65261)

 

 

1 Accepted Solution

Accepted Solutions

yes if you want to route only source based then PBR is the  option you have and best option to test.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

is the new igb have different IP range  ? or you going to use same IP address ?

 

you can do with PBR for that specific range to route to new G0/7

 

here is example :

 

https://www.networkstraining.com/cisco-asa-policy-based-routing-pbr/

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Different IP completely.   Original one starts with 216.x.x.x while the other starts with 12.x.x.x

Is policy based routing really the only option?   I did see that but was hoping there was an "easier" solution :-)

 

yes if you want to route only source based then PBR is the  option you have and best option to test.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card