01-04-2016 01:34 AM - edited 03-12-2019 12:05 AM
Hi
Do you know if there is the ability to route traffic based on application type on ASA NGFW with Firepower? - I know we can inspect application data but can we do more when we know what the application is?
e.g. 2 x internet connections, based on "application type" route via ISP1 or ISP2 .....effectively route non critical traffic via ISP1 (Facebook,web and critical traffic via ISP 2.
Cheers
James
Solved! Go to Solution.
01-04-2016 05:34 AM
No, you can not do this. You can only route based on the destination address, which will sometimes do the trick.
You need a router and PBR to do this.
01-04-2016 05:34 AM
No, you can not do this. You can only route based on the destination address, which will sometimes do the trick.
You need a router and PBR to do this.
01-04-2016 05:47 AM
Many thanks for your response
Regards,
James
01-04-2016 06:54 AM
You can do that, but not inside of FirePOWER. Routing is purely done on the ASA and there you have PBR available. With that you can send traffic based on the destination-port out of a particular link. You can find more info on PBR in the config-guide.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide