01-06-2015 10:08 AM - edited 03-05-2019 12:30 AM
Currently running ASA 5545 (ASA version: 9.3(1)) with one 200 MB Internet connection connected to ASA via Cisco 3845 .
Recently installed second ISP (not used at this time) with a 10 MB connection with a separate Cisco 3845 (will be used for failover)
Just received from ARIN AS Name/Number and block of IPV4 addresses.
Questions, what is the best blueprint to address of our needs.
Do I use the second connection as a “failover” or do I increase the connection speed and use both connections.
I know I have to work with both providers to enable routing between them but what to use, BGP ?
Any white papers to address this would be grateful !
01-06-2015 11:37 AM
Here is good link to start with
http://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/13762-40.html#conf5
As far BGP or not, with service providers, you usually have two choices, BGP or static. With static you usually use a default route to each provider with different admin distance so one is primary and the other one backup. With BGP, you have a choice of default routes, partial routes or full routing table. Since you are using older devices (Cisco 3845) it is probably a good idea not to get the full Internet routing table which is about 600k right now. If you want to use BGP talk to your providers and maybe receiving a default route is a better choice.
HTH
01-06-2015 11:40 AM
What about configuration of the ASA, what is the best topology when terminating two ISP's on the ASA, thanks.
01-06-2015 11:55 AM
I have never done it on ASAs. Most people terminate their circuits on routers and keep the firewalls as security devices sitting behind the routers and do NAT, VPN, etc on them.
01-06-2015 12:02 PM
Correct the ASA will continue to do NAT, VPN, etc. but looking at this paper
https://supportforums.cisco.com/document/139051/dual-isp-implementation-asa I have several options to think about.
01-06-2015 12:52 PM
It can be done on ASAs as long as the providers are handing off Ethernet to you. You just have to size the ASAs to make sure it can handle everything you need.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide