04-03-2019 05:40 AM
Hi,
Following scenario…
We have a Cisco ASA firewall with ONE default static route to our external interface with a fast connection to the internet.
Besides this we have another external interface which has also internet connection but over a different ISP and much slower.
I have configured a Route-Map on an internal interface to route special traffic specially to this slower connection.
Everything works fine.
When I disable the external interface on the ASA with the slower internet connection, the traffic is automatically routed through the faster connection to the internet, which is also fine.
BUT… when the interface with the slower connection stays up even there is no internet connection… the traffic is not routed automatically over the faster connection.
I can configure over ASDM a “next hop verify availability” in the route-map under the tab “Policy Based Routing” (sequence number, ip address and tracking object id) but it doesn’t work and I guess I have to configure something else.
What do I have to configure additionally so that the special traffic is routed automatically to the faster connection when there is no internet connection on the slower interface?
If possible please explain the way over ASDM :-)
Thx!!!
Regards
Mike
Solved! Go to Solution.
04-05-2019 06:58 AM - edited 04-05-2019 07:01 AM
Thanks for your help but I actually don't want to have a second default route.
I've actually been looking more for this solution:
sla monitor 1
type echo protocol ipIcmpEcho NEXT-HOP-IP interface EXTERN-INTERFACE
frequency 10
timeout 5000
sla monitor schedule 1 life forever start-time now
track 1 rtr 1 reachability
route-map RM-NAME permit 10
match ip address ACL-NAME
set ip next-hop verify-availability NEXT-HOP-IP 1 track 1
Regards,
Mike
04-03-2019 06:53 AM
Hi,
Here is the ASDM guide:
If you want commands then share your current running configuration.
04-05-2019 06:58 AM - edited 04-05-2019 07:01 AM
Thanks for your help but I actually don't want to have a second default route.
I've actually been looking more for this solution:
sla monitor 1
type echo protocol ipIcmpEcho NEXT-HOP-IP interface EXTERN-INTERFACE
frequency 10
timeout 5000
sla monitor schedule 1 life forever start-time now
track 1 rtr 1 reachability
route-map RM-NAME permit 10
match ip address ACL-NAME
set ip next-hop verify-availability NEXT-HOP-IP 1 track 1
Regards,
Mike
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide