01-10-2011 01:34 AM - edited 03-04-2019 11:00 AM
Hi,
We have Cisco 3845 and Cisco ASR 1000 Router.
In current scenario like that,
Internet Link-->Router 3845-->Cisco IPS-->--------Cisco 3750 SW configured with layer 2-------->
Cisco ASA active and Failover{connected to 3750 SW.}------>Cisco 6500 Chassis ----> campus Switches
So Campus users having default gateway of Cisco ASA inside IP, also NAT,Security Policy are done on ASA.
IP address details:
69.X.X.X Series(Outside)-----Cisco 3845-----59.X.X.X/24(Inside)------->Cisco IPS(172.X.X.X/16)------>Cisco 3750 SW(no ip add)<-----59.X.X.X/24(outside)---Cisco ASA-----(172.X.X.X/16)------->Cisco6500(172.X.X.X/16-Flat network*No vlan)
We want to use another Cisco ASR router which also having Internet Link which is connected to another ISP means both ISP are different.
ISP-1(Currently using)- having /24 public IP pool and ISP-2(want to use)-having /29 Pool.
How to use both ISP's Internet link using load-balancing?
- Vaibhav
01-10-2011 02:30 AM
Hi,
Are the Public IP's are registered to your company I mean you have your own AS. I think you can use GLBP to have load balance the traffic. If we get into BGP you need to tune lot of attributes at ur end as well as ISP end.
01-10-2011 03:45 AM
Hello,
Thanks for your reply,
The ISP-1 and ISP-2 pool has been registered with our company.
But I have a query,when we use GLBP the mac-address will be same means, when user send a ARP massage to gateway,it will be ASA's inside interface MAC address,(in user arp table the gateway is mapped with ASA inside mac address.) then ASA forward the packet to router then source mac address changed to ASA's outside interface mac address, AVG receive the request from same mac address, then how it will load-balance & another problem is the private IP pool NATted with ISP-1 public ip addresses.
- Vaibhav
01-10-2011 05:50 AM
Two default routes pointing out different interfaces is not supported on the ASA.
GLBP is indeed not an option because the ASA is the only device doing ARP requests and because you have different subnets on different interfaces.
The best way is to get PI address space and do BGP with both providers.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide