cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2338
Views
0
Helpful
2
Replies

Conditional NAT and routing on ASA

bapatsubodh
Level 1
Level 1

Hi,

On our ASA 5510 we already have one ISP link terminated on outside interface. There is correspoinding nat and global configured for outbound access to internet.

Now we need to terminate second ISP link on one of the DMZ interface to have redundancy for the primary ISP. 

When primary ISP link or router is down we need to send all the traffic to secondary ISP router.  How do we configure NAT and global for this condition that only when primary is down then only this NAT -Global should be used.  Do we have anything like object tracking associated with the NAT-global.

So that as long as Primary  RTR - object is up ASA will use the first NAT-Global pair. When primary ISP is down RTR-Object is not reachable then ASA will perform the second NAT-Global operation.

Also can we have default route pointing to Outside interface (primary ISP router) and in case of primary router failure it will point to secondary ISP. Do we have "track"  in the static route commands on ASA.

Please share the experience.

Thanks in advance!

Subodh

2 Replies 2

bapatsubodh
Level 1
Level 1

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

This is similar to our requirement. But still not clear how NAT -Global will work if primary ISP WAN link is down. Outside interface will still be up and ASA will use the first pair to source NAT the packets. How and when ASA will start using second ISP for NATing?  Track will be used to put the correct route in routing table but not clear about NAT-Global.

Thanks in advance.

Thanks

Subodh

When the primary route is removed from the routing table and the backup high metric route is added in the routing table all subsequent internet conns will take the new backup path as the egress interface and will be forced to take the global for that backup path.

You can review a few options that I have listed here:

https://supportforums.cisco.com/docs/DOC-13015

-KS

Review Cisco Networking for a $25 gift card