06-05-2008 07:31 AM - edited 03-11-2019 05:55 AM
Is it possible to use a pair of ASA 5520's in Active/Standby mode with a seperate ISP for internet access and VPN access? We want to seperate Internet and VPN traffic.
06-05-2008 08:57 AM
What do you mean by 'VPN Traffic'? An MPLS-Based IP-VPN provided by a DSP? Or this is your WAN Intranet sort of link, on which VPNs will be terminated? Anyway both these cases are possible as long as you don't need a default route. Because the ASA cannot have two default routes pointing to two different interfaces. As you know Internet will (almost) always require the default route.
Regards
Farrukh
06-05-2008 10:08 AM
By VPN traffic, I mean that we will have to seperate connections to the internet by different ISP's. One connection will be used for access to the internet (web browsing) and the second for IPSEC and SSL VPN connections to different small offices. To make this work, would I configure two outside and two inside interfaces? Are there any docs I can look at? Thanks.
06-05-2008 11:04 AM
Yes this can be done, please have a look at this:
Regards
Farrukh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide