cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
315
Views
0
Helpful
1
Replies

Pix 501 to DUAL 3005 with different ISPs (and Public IPs)

phillip.tyre
Level 1
Level 1

For the sake of redundancy we are looking to move away from a configuration with remote 501s connecting to one central 515Eur with site-to-site tunnels. We will soon have two T1s from two different ISPs each with separate public IP address space (No BGP).

We are leaning towards the direction of having two 3005 concentrators each with a different public address connecting to a different ISP.

The way I understand it we can use OSPF and reverse route injection on the private interfaces of each 3005's while terminating them in the same VLAN along with one of the 515's DMZ interfaces also configured with OSPF. If 2 peer entries are made on the remote 501's then they can figure out if which one of the T1's are up and use the appropriate concentrator.

Will this work?

Is there a better way to do this? We would like for the 501s to use which ever peer wasn't experiencing congestion if possible. It will not be necessary for the remote networks to talk to each other.

.

1 Reply 1

umedryk
Level 5
Level 5

looks like a good design to me...

Review Cisco Networking for a $25 gift card