02-09-2012 07:40 AM - edited 03-04-2019 03:12 PM
Hi,
At the moment I'm running a T1 to a Cisco ASA 5505 device. I'm in the process of getting a backup ISP. My question is, is it possible to configure this firewall with two ISPs so that the same internal webserver can be accessed via backup ISP?
Thanh
02-09-2012 08:18 AM
Back up internet you can always configure but can not use backup link until primary fails.
Thanks
Ajay
02-09-2012 10:46 AM
Still this does really answer my question. Will I be able to access my website from the backup isp?
Thanks
Thanh
02-09-2012 11:06 AM
The issue you will have is with the DNS needing to be changed to the the backup providers ip when the primary goes down.
Here are some ideas to make this happen,
Option 1. Work with both providers to support routing BGP to you
Option 2. Each ISP will give you a different range of ip addresses, Setup static mappings / forward ports from ips from both providers assigned ips to the same internal webserver or if is dhcp just forward the port from assinged address. Then use a third party DNS provider that allow forwarding with redundancy.
Option 3. Utilize dynamic DNS with a third party DNS provider.
02-09-2012 11:11 AM
Answer is NO.
02-10-2012 05:35 AM
Thanks Daniel, I will try that.
Thanh
02-10-2012 05:56 AM
Hi,
1. ASA doesn't support BGP
2. ASA doesn't support load balancing but only primary/backup failover with static routing and tracking feature
3; as far as I know DynDNS client is not supported on ASA
Regards.
Alain
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide