01-10-2016 07:45 PM - edited 03-12-2019 12:07 AM
I can hardly believe it. ASA 9.4 has added proper PBR support.
http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html
01-11-2016 05:41 AM
Hi Philip,
That's true. PBR is now supported on ASA from version 9.4.1. Customer would now be able to run PBR directly from ASA. They now need not to be dependent on Next Hope device to support Dual ISP based Scenarios. Source Based Routing is now supported directly from ASA. :)
Regards,
Akshay Rastogi
01-11-2016 12:30 PM
I was doing some testing yesterday and had some issues with 9.4(2). It broke AnyConnect with certificates. However 9.5(2) seems to make everything work again. I feel a new gold star release candidate coming up in 6 months.
01-11-2016 01:32 PM
Hi Philip
Just out of interest do you know why it broke it ?
I only ask as a thread in LAN you answered has an issue with PBR and wondered if it might be the same sort of thing -
https://supportforums.cisco.com/discussion/12744756/asa-5512-9423-policy-based-routing-pbr-stateful
Jon
01-11-2016 03:34 PM
What was happening is 9.4(2) was ignoring the configured trustpoint, and using the self generated certificate.
Alas I have just discovered that IKEv1 user to site VPNs seem to be broken in 9.5(2).
Not having a good day with my experiment.
01-11-2016 09:12 PM
My first day of trying to use PBR and I crashed and burned.
The ASA had an existing 10Mb/s symmetric fibre circuit, and we were adding a new 200Mb/s symmetric PPPoE circuit. The customer wanted all web browsing to go down the 200Mb/s circuit.
I was using the "set interface" option to set the output interface. Well, PBR on an ASA wont use the specified output interface unless there is already a route in the routing table.
Being PPPoE it is not possible to add a static route via it. Because the customer has an existing fibre circuit a static default route existed via that. PPPoE would not install a default route because of the existing static route.
End result, impossible to use PBR to select the output interface.
In this case we had already sold the customer an ISR 4331 for doing the policy routing, so back to plan 'A'.
01-12-2016 06:17 AM
Good job you didn't know about PBR on the ASA before you sold the customer a router :)
Jon
07-16-2017 07:30 PM
The default route is to the 10Mb/s symmetric fibre circuit,not use 0.0.0.0 0.0.0.0;
change to this two route 0.0.0.0 128.0.0.0 and 128.0.0.0 128.0.0.0
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide