06-05-2018 05:07 AM - edited 03-08-2019 03:15 PM
Hello,
If I have 2 providers, and one device will comunicate uplink via ISP1 and dowlink via ISP2, will it be a problem ? Please see picture in attachement.
Thank you.
06-05-2018 08:24 AM
Hi,
Multihoming to 2 different providers should not be an issue.
HTH
06-05-2018 09:12 AM
06-05-2018 12:08 PM
I believe that Joseph has identified an important issue about address space being used. Another potential issue is the type of device used for the Internet connection. The drawing shows something that looks like a switch. And that would be ok. But if the device were something that did stateful inspection (as many firewalls like ASA do) then the asymmetric path would be a problem.
HTH
Rick
06-05-2018 11:55 PM
Hello, Thanks for your replies.
@Joseph W. Doherty - There are two independent IPs from different ISPs, so it should be okay.
@Richard Burts - Yes, as you assumed, there is Cisco ASA, which has a statefull inspection.
So, is there any way to solve it and keep routes as it is in drawing?
Thank you
06-06-2018 03:03 AM
06-06-2018 11:39 AM
The drawing in the original post was quite simple. It showed a host connected through a device that appears to be a switch to 2 ISP with traffic going through one and returning via the other. Now we are finding that the situation is more complex than that. There are different IPs and there is an ASA firewall. We really need a better understanding of the environment to be able to give good answers.
But based on the incomplete information that we have so far I would suggest these points:
- if we have an IP packet whose source address is a Green address and we send it out through the Red ISP then it should come back to us from the Green ISP. This assumes that the Red ISP accepted the packet with a source address that was not one of its networks. Some ISPs have restrictive policies about what source addresses they will accept (one of the motivations here would be to prevent address spoofing), some do not have restrictive policies, and some are willing to negotiate about what they will accept. We do not know which category the Red and Green ISP fall into.
- for devices like ASA when a packet goes out one interface it expects the response to come through that same interface (this is one of the essential aspects of stateful inspection). It is not clear in the drawing where the ASA is and whether both ISP might connect through the same ASA interface or connect through different interfaces.
HTH
Rick
06-07-2018 05:10 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: