07-31-2019 12:16 PM
Here is my case. I currently have a Cisco ASA5545 running ASA 9.8(2) / ASDM 7.9(2)152. The firewall is up and running with several VPNs and internet access, etc. We just received a new 1GB internet circuit which we want to test for a while before cutting over.
--------------------------
For reference;
G0/0 - Outside
G0/1 - Inside
G0/6 - ATT_Inside_Test
G0/7 - 1GB_ATT_TEST
--------------------------
I used ports G0/6 for my "test" internal network (192.168.69.0/24) and configured G0/7 for my new 1GB circuit. Now there is a default route already set that forwards traffic out the original internet port (G0/0 named Outside).
How can I set this up so that only users on the new test network of 192.168.69.0 network with go out the new (G0/7) 1GB interface for internet access while all other users continue to use the original G0/0 interface?
I did try to set this up for some testing but it appears not matter what I do or try even the traffic on the 192.168.69.0 net still wants to go out the "Outside" interface (G0/0) and not the new 1GB Interface (G0/7).
Is what I'm asking for even possible? Obviously this is a production firewall so I am very limited on drastic configuration change options.
Here is one example.
6 | Jul 31 2019 | 15:12:09 | 302015 | 192.168.69.69 | 65261 | 66.109.38.250 | 53 | Built outbound UDP connection 175781294 for Outside:66.109.38.250/53 (66.109.38.250/53) to ATT_Inside_TEST:192.168.69.69/65261 (192.168.69.69/65261)
|
Solved! Go to Solution.
07-31-2019 12:48 PM
yes if you want to route only source based then PBR is the option you have and best option to test.
07-31-2019 12:23 PM
is the new igb have different IP range ? or you going to use same IP address ?
you can do with PBR for that specific range to route to new G0/7
here is example :
https://www.networkstraining.com/cisco-asa-policy-based-routing-pbr/
07-31-2019 12:25 PM
Different IP completely. Original one starts with 216.x.x.x while the other starts with 12.x.x.x
07-31-2019 12:26 PM
Is policy based routing really the only option? I did see that but was hoping there was an "easier" solution :-)
07-31-2019 12:48 PM
yes if you want to route only source based then PBR is the option you have and best option to test.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide