10-05-2006 09:11 AM - edited 03-03-2019 02:14 PM
Router is a 1760 with 2 T1 WICs
We have added a 2nd T1 Internet connection to a different ISP. By default, all traffic will go out the 1st connection because it's route has a lower weight.
We would like to have VPN traffic leave the same connection that it is coming in on (the 2nd connection). How can I accomplish this with PBR?
The VPN traffic is being handled by an ASA5510 that is using IPSECoverUDP aand IPSECoverNATT.
10-05-2006 11:15 AM
Do you have multiple public address spaces?
10-05-2006 11:29 AM
We have an available address space for each ISP. We are currently only using the address space from the "old T1". We have addresses from that space assigned to the ethernet interface on the Internet router, and to the ASA5510 for VPN access and for a few 1-1 NAT connections.
10-05-2006 12:12 PM
PBR with VPN could get messy. I would use the second address pace and have the VPN's use that as the endpoint. That would be a DMZ interface on the ASA5510.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide