cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1084
Views
0
Helpful
1
Replies

two active active ISPs with load balancing, publishing and VPN connection

saulatsaleem
Level 1
Level 1

Hi,

I wonder how to enable a scenario where i have to use  two ISP's to share 30/70 load on our internet traffic, have to configure almost 60 internal websites already published using microsoft TMG firewall and connect client VPN connections and site-to-site vpn connections. I know that ASA firewall has limitation when using security contexts. Is good idea that how to achieve this gool?

I previously tried connecting four sites running ASA devices with this fifth site running Microsoft TMG firewall but i was able to connect only two ASA firewalls using site-to-site VPN, though I was able to connect remaining two as well but last two were not able to access ASA-TMG resources. furthermore behavious of two ASA-TMG connected sites was strange: sometime i was not able to access cross site resources from one machine but was able to do so from another machine.

I noticed that two of ASA sites connected with TMG site has different internal IP class (e.g site one 192.168.0.* and site two using 172.16.*.*) while remaining two have same class like the first site e.g 192.168.128.* and 192.168.100.*

Did anyone has experiance connecting TMG-ASA with multiple sites within same IP class scenario?

OR

How to enable same features using Cisco devices as they are on a single Microsoft TMG?

Best,

Saulat (Contact# 0092-321-4025587)

1 Reply 1

Kureli Sankar
Cisco Employee
Cisco Employee

Sulat,

You can load balance between the two ISPs. That is not possible. But, we do have some options that I have discussed here:

Hope the above link gives you some ideas to utilize both your ISP links.

-Kureli

Review Cisco Networking for a $25 gift card