cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
277
Views
0
Helpful
1
Replies

Default route distribution over OSPF for ASAs

Bracebridge
Level 1
Level 1

Folks,


I have a problem with an ASA (5520), running asa944-16-smp-k8, not accepting a default route via OSPF. Below is a description of my setup:

Have two internet service providers which connect to the two routers on GI0/0s. Let's call them outside interfaces. Each interface configured as a /30 to the upstream service provider router. My routers receive a default route via BGP, and manipulate the AS path via prepend command so that all return traffic goes through a specific provider. Pretty much standard setup.

Behind the routers, I have three devices: two ASA 5525 (in active/standby config), acting as my mail firewall, and an ASA 5520, functioning as a standalone VPN device. All routers (GI0/1s - "internal" interfaces), and ASA's outside interfaces are tied together via OSPF in area 0. Both routers redistribute the default route from BGP  via redistibute OSPF command. I preference my preferred route using higher metrics on the injected route. As a result, I have two 0.0.0.0 routes on my firewalls, with only one being active. This is the intended behavior, and it works well if I need to failover onto another provider. But, my VPN router does not have any default routes. It participates in OSPF, can see all neighbors and is receiving the LSAs. The only config difference between the VPN ASA and the firewall ASA is that the firewall, being my gateway for all outbound traffic, has default-information originate configured. Since my VPN ASA handles only VPN traffic, I never needed it to be a default gateway...

So my question is whether I need to configure default-information originate configured on the VPN ASA in order for it to receive the distributed  default routes. And if it is so, how should I set up the metric on it so that its outside interface never becomes the default gateway.

Thank you,   Paul

1 Reply 1

Harold Ritter
Level 12
Level 12

Hi Paul,

 

You can't redistribute default route from BGP into OSPF using the redistribute command. You need to use the default-information originate.

 

Can you verify that you really have the default route (0/0) in the ospf database (show ip ospf database ext).

 

Regards,

Harold Ritter
Sr Technical Leader
CCIE 4168 (R&S, SP)
harold@cisco.com
México móvil: +52 1 55 8312 4915
Cisco México
Paseo de la Reforma 222
Piso 19
Cuauhtémoc, Juárez
Ciudad de México, 06600
México
Review Cisco Networking for a $25 gift card