03-03-2020 06:05 AM
So I have an ASA Dual homed using IP SLA with tracking for my routes to set outside1 as the primary link:
nat (any,outside1) after-auto source dynamic Internal interface
nat (any,outside2) after-auto source dynamic Internal interface
route outside1 0.0.0.0 0.0.0.0 XXX.XXX.54.XXX 1 track 1
route outside2 0.0.0.0 0.0.0.0 XXX.XXX.108.XXX 254
The issue is that somehow a few devices are getting NATted to XXX.XXX.108.XXX (outside2)
How can I prevent devices from NATting to outside2 unless outside1 is down?
Thanks for your help!
03-03-2020 08:28 AM
The issue is that somehow a few devices are getting NATted to XXX.XXX.108.XXX (outside2)
i beiieve you should use below syntax for the backup route
route backup 0.0.0.0 0.0.0.0 XXX.XXX.108.XXX 254
refer below guide :
03-03-2020 09:31 AM
Hi,
Maybe at some point the SLA went down and thus routing/NAT changed? For those IP's which get NAT'ed by the second NAT statement, run a "packet-tracer" and see which route/NAT entry does it match.
Regards,
Cristian Matei.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: