cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3961
Views
10
Helpful
7
Replies

FTD 1010 with dual ISP

Dears i have topology as picture,

i want do divide inside network as from IP (192.168.1.1- 20) get out from ISP1 and other IP (192.168.1.21-200) get out from ISP2

i try the PBR with the help of FlexConfig in  this video but not work.

https://www.youtube.com/watch?v=lakHhw9CR5Y

can any one help me?

 

FMC.jpg

 

This Video show how to configure PBR using FMC FlexConfig. Correction: During Flex-Configuration, instead of applying Route-map on Ethernet 1/1 & Ethernet 1/3 which is outside. It should be applyed on Ethernet 1/2 (Inside Interface). Linkedin: https://www.linkedin.com/in/nandakumar80/ For Latest ...
7 Replies 7

Hi,

What is your PBR configuration? Please provide screenshots

Is that the full configuration? You don’t appear to have the “match ip address” command under the policy maps.

I assume you’ve applied the configuration to the outside interfaces? The policy-map should be applied to the inside interface.

@Rob Ingram 

I  dont understand you, can you explain to me?

You need to define the source networks using the "match ip address" command in the policy-map.

 

Traffic is routed based on the source IP address, you need to apply the policy-map on the inside interface - traffic will then be routed out of the correct outside interface as determined using the PBR policy-map configuration.

 

Refer to the following links for more information:-

https://www.slideshare.net/redouanemeddane/policybased-routing-using-flexconfig-firepower-threat-defense

https://www.ciscozine.com/pbr-route-a-packet-based-on-source-ip-address/

@Rob Ingram 

i apply this configuration and apply it on inside interface but all inside still using one ISP and failover didn't work 

Capture.JPGCapture2.JPG

HI all,

when I deploy the flex config i get this warning but its deployed without any problemerror deploy.JPG

 

Review Cisco Networking for a $25 gift card