Hi,
We peer with our ISP over dual Internet Circuits. Our Anyconnect infrastructure is a pair of ASA's with a Load Balance address. Pretty standard.
Currently we are advertise the public addresses for the Anyconnect infrastructure out of both our uplinks to our ISP via BGP with 1 link being preferred over the other (AS Prepend/Local Pref) style. So effectively one link is the backup.
Now my question is if we manipulated BGP so that the outside Anyconnect GW1 IP preferred one link and the Anyconnect GW-2 IP the other link with the LB address down the Primary. Presumably the clients would hit the LB address then connect down either the A or B uplinks to the physical addresses? Would that work or completely break it?