07-15-2024 06:44 AM
Hello Team,
I have a setup as attached,
I recently added isp b for redudancy.
My vpns terminata at ftd level, on [66.0.10.10] - this is an example IP.
on asa have done an acl called outside_in allowing any to connect to 66.0.10.10. and equivalent access-group config.
once ispb came up, ra vpn to 66.0.10.10 kicks me out, not able to authenticate and connect.
for secondary isp i did another acl, but now on internet zone in as the acl and access- group?
what could i be missing, what could i be doing wrong?
the desired state is once isp a is down b picks automatically and services are not disrupted.
Will appreciate your insights.
Thanks in advance.
07-16-2024 08:59 AM
Perhaps you should check for asymmetrical routing. If your VPN session is going out to ISP A, but returning via ISP B I'd wager the firewall will not allow it. You'd need to make ISP A the preferred path in and out.
Hope this may be of some help
07-17-2024 02:12 AM
I have done so, by using weight metric, isp A has larger weight.
Is this not enough do i need to use another metric to avoid assymetracy?
in regards to acl-ins, did i do it right?
07-18-2024 05:04 AM
The weight metric only applies to the local router's choice outbound and does not influence the return traffic. You probably need to prepend your AS to ISP B so that ISP A would be preferred.
As far as the ACLs are concerned, my assumption would be if ISP B is supposed to be the backup for ISP A, then they should mirror each other.
07-25-2024 10:37 PM
will test this by applying the as prepend attribute, and update here on the findings.
its on prod net, so am waiting for the cr to be approved.
thank you.
07-25-2024 02:56 PM
Your Q in other post about vpn work only when asa have defualt route is relate to this design issue.
So can ypu elaborate more
Asa have two ISP and ftd behind ASA use public IP for VPN ? Or it use private IP and ASA do NATing to public IP?
MHM
07-25-2024 10:36 PM
for initial test case, have used private IP on FTD natted at ASA.
but on final prod network, i will have a public IP on FTD; p2p IP of /30 between ftd and asa.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide