cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1100
Views
0
Helpful
9
Replies

PBR with ASA 5525

Dear All,

I have ASA 5525 in which two ADSL connected with fixed IP address. ASA inside interface connected to a layer 3 - 3750 switch in which four vlans are configured.

Plan:

Planning to route all internet traffic on one ADSL line and other one dedicated IPsec VPN connection for remote users.

Question:

As ASA do not support for PBR, is it possible to enable PBR on layer 3 switch and achieve my requirement? If possible, can you guide me how can i do that? 

9 Replies 9

Dear, thanks for your reply. How can i achieve my requirement if can explain that will help me.

For me it's not clear how your network is set up. How exactly are the ISPs connected and what did you want to solve with PBR?

Dear , Thanks for your reply.

I have two adsl connection connected to ASA with PPPoE configuration (they are Static IP) and inside interface connected to a layer3 switch.

Now, i want to assign one line for all kind of internet traffic and other adsl line only for IPsec connection for remote users.

How can i achieve my requirement either using PBR or any other mechanism. Got confused, because most of the discussion says not possible to achieve this particular requirement.  if you have any solution , suggestion kindly explain me in details. Thanks for your support.

For that you don't need any PBR. You configure the Internet-ADSL with the active default route. The VPN-users use the IP of the second ADSL line for their connections. The ASA will send all traffic to the internet through the first ISP, all answer-packets for the VPN will leave on the interface where the connection terminate.

Thanks for your reply.

Since, both the interface configured as PPPoE they are connected interface. So where do you want me to configure the static route to pass all internet traffic to particular ADSL line?

Thanks for your support.

That's controlled by the administrative distance (in ASDM/CLI it's named Metric) that you assign to your PPPoE-session. Your primary line typically has an AD of "1" (which is the default) and the second line that you want to use with VPN has something higher.

Dear Thanks for your support.

When i configure PPPoE , its taking IP address from ISP (either DHCP or static) along with gateway address. Still you want me to configure two static route along with different AD value. Can explain please? Thanks for your support again.

No, not a static route, it's inside the interface config.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: