cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1141
Views
0
Helpful
3
Replies

Cisco ASA dual ISP with different services

J_Vansen_S
Level 3
Level 3

Hi All,

I have been assigned a task to deploy an additional ASA firewall to a existing customer network.

Current infra

  • 1x Cisco ASA that is used for internet traffic and MS_Exchange Mail traffic

Proposed new infra

  1. Additional Cisco ASA
  2. Used for Remote access vpn (Anyconnect)
  3. DMZ access

Concerns

  1. All of internal users/VLAN will be going to the internet via ISP 1 (default route to ISP1).  My web&app services is hosted on ISP2.
    • Would like be an issue?
  2. A few of the internal users within the same VLAN/subnet would like to use the ISP2. Is that possible?

Please advise

3 Replies 3

Tagir Temirgaliyev
Spotlight
Spotlight

Hi

A few of the internal users within the same VLAN/subnet would like to use the ISP2. Is that possible?

yes it is.

few of the internal users within the same VLAN/subnet can use the ISP2, they need default route to ASA2

However all users default route is on the L3 Core Switch. How do i achieve this instead?

There are many ways

1. Another one vlan  for that  few  internal users

2. PBR on core for that  few  internal users

3. put asa2 in the same vlan where users