To configure the ASA to send traffic through both ISPs simultaneously.
Usually when a user has two ISPs terminating on the ASA, the ASA is configured for ISP redundancy. However in some cases, the user would like to use both ISPs simutlaneously to send traffic.
In such a scenario, the best solution would be to use a router. Using route-maps on the router, one can configure the routing in such a way that only certain kind of traffic uses one ISP while the second ISP is used for other kinds of traffic. Although the ASA supports route-maps, because it wasn't designed to support extensive routing capabilities, there are quite a few features under route-maps like source-based routing, which are not supported by the ASA. If using a router is an option then the network would have to be redesigned as follows:
If however, this is not an option, then it is possible to configure a very crude form of "loadbalancing" on the ASA. The following two scenarios are ways in which both ISPs can be used simultaneously on the ASA:
1. Route traffic based on destination:
As I mentioned aboved, the ASA is not a load-balancer or a packet-shaper. However with the following commands on the ASA, we can route traffic to half the destinations on the internet using ISP1 and the other half using ISP2:
nat (inside) 1 0 0
global (ISP1) 1 interface
global (ISP2) 1 interface
route ISP1 126.96.36.199 188.8.131.52 184.108.40.206 // creates a default route for addresses in the first half of the IPv4 spectrum
route ISP2 0.0.0.0 220.127.116.11 18.104.22.168// creates a default route for addresses in the second half of the IPv4 sepctrum
2. Route traffic based on destination ports:
By adding the configuration below, the ASA can be set up to send web traffic(http,https) out through ISP2 and all other traffic is sent through ISP1 as shown above.
Dear experts, I've setup a DVTI with IKEv2 to get remote access into my 2901. However, the IKE session establishes, without any errors, the interface comes up, but no IP address is assigned to the Virtual-access interface. The client is a C881 runnin...
I am trying to setup my Stratix 5950 switch for Many to One NAT configuration using NAT rules in ASDM wizard.My Inside1 interface is already configured for VLAN 10 with IP 192.168.10.xx. The Outside Interface1 at 192.168.20. xx has a PC connected with IP ...
After upgrading to the last firmware available in your repository (22.214.171.124) to a RV110W, this notice is logged after the router start up: "Linux version 2.6.22 (zls@cybertan-team2) (gcc version 4.2.3) #47 Wed May 27 10:33:03 CST 2020"A quick search r...
Hi everyone, I have a bunch of Cisco 4321 Routers that I want to configure ACL on but I am running into some difficulties. I have an Internal Server connected to Router 3 that is using the Windows Time Service which acts as the NTP Server for the 3 R...