cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
303
Views
0
Helpful
8
Replies

ISP Link Failover in ASA 5520

Muthukumar P
Level 1
Level 1

Hi Team,

                  One of our client is having ASA 5520 with two ISP Link..Customer is expecting that Mail traffic flow to dedicated one ISP and remaining traffic flow to other ISP.If any one of the ISP goes down all traffic should work to availability ISP Link. Please help on this .

Thanks

Muthukumar

8 Replies 8

That's easy: Replace the outdated legacy ASA with an ASA-X and configure Policy-based routing. Ok, one part of this might not be that easy. But that's a task for the feature PBR which got introduced to the ASA in newer releases which is not available for the older models.

HI ,

    I have attached  ASA 5520 Tech support and Traffic flow details . Please find it and confirm that this model is support for PBR if supported please share the configuration document..

  and one more thing customer is having two firewall , ASA in outside and cyberoam is Inside firewall.. Please help suggest how achieved the target..

Thanks

Muthukumar

Muthukumar

Support for PBR was added in release 9.4. Your 5520 does not run code that supports PBR. So unfortunately I must confirm that your 5520 does not support PBR.

HTH

Rick

HTH

Rick

HI,

        You are talking about IOS version.. if yes  I will upgrade the suggested  IOS version 9.1.7..

Please confirm and if share the PBR configuration URL as well..

Thanks

Muthukumar

Muthukumar

PBR is not supported in 9.1.7. PBR is supported beginning in 9.4. I do not believe that 5520 can run that version of code.

HTH

Rick

HTH

Rick

Hi ,

        Thanks for your response, I will inform to customer ISP link fail over only possible.. But One of other customer raising same query but they are having ASA 5525X.. Can you help me PBR routing document for this scenario..

Thanks

Muthukumar

After looking again at your traffic-flow- document, do you want to control outbound or inbound traffic? As already mentioned, outbound would be done with PBR which is not available for your platform. But for inbound traffic, you could use both of your ISPs. So, what exactly do you want to achieve?

Review Cisco Networking for a $25 gift card