09-01-2011 08:16 PM - edited 03-07-2019 02:00 AM
Hi all,
Hope someone can assist some Cisco noobs,
We have a network with two ISP's each connected to a seperate ASA5510. We can't use BGP with either ISP, so in order to to determine the state of the ISP links we're using object tracking from the ASA's to ping a router in each ISP's network. If the tracked object is up the route is advertised into the routing table and can be distributed via OSPF to the internal network. That works fine as long as there's a default route on the ASA for test pings to reach the tracked object.
The problem now is that we'd like to use object tracking to check that the default route is up. However, if there is no default route to begin with (eg after reloading the ASA) the test pings can't reach the tracked object and so the router can't establish the default route. We can't simply create a static default route with a higher metric than our tracked route because it would be advertised to the rest of the network whether the ISP link was up or not. It's a chicken-and-eg scenario where the test pings don't know the route to the tracked object (the ISP's router) until the tracked object is up and creates a default route.
So the question is how can we ensure the ASA's object tracking pings to our test object (the ISP's router) always exit via the ASA's external interface rather than via another route the ASA may pick up from OSPF?
Any help or tips are appreciated,
09-01-2011 08:34 PM
Add a static host route with the ip address of the ISP router.
09-02-2011 12:10 AM
yes the above poster is correct
adding static route for the next hope ISP IP will help
as ASA dose not support PBR, if it was router you could have made a localy policy routing to redirect the icmp generated by the router to the isp next hop
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide