Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > ASA with two ISP's

Reply
Thread Tools

ASA with two ISP's

 
 
Mr. Ian
Guest
Posts: n/a
 
      03-27-2007

Is it possible to have the following scenario with an ASA 5510?

ISP1 - Fast, cheap, asymmetric, unreliable bandwidth (e.g. Cable).
ISP2 - Slower, reliable, symmetric bandwidth (e.g. T1).

LAN ---- ISP1
\ /
ASA
/ \
DMZ ---- ISP2

I woud like ISP1 one to receive all outgoing LAN traffic (i.e. general
office Internet traffic).

I would like ISP2 to be used for any incomming connections to the DMZ
and to maintain our VPNs to remote sites.

In the event ISP1 is down, outgoing LAN traffic would be re-routed to
ISP2.

In the event ISP2 is down, VPN connections would be re-connected via
ISP1.

Thanks for any help. I'm just trying to get an idea of what's going
to be involved in making this type of setup work.
 
Reply With Quote
 
 
 
 
Brian V
Guest
Posts: n/a
 
      03-28-2007

"Mr. Ian" <> wrote in message
news:...
>
> Is it possible to have the following scenario with an ASA 5510?
>
> ISP1 - Fast, cheap, asymmetric, unreliable bandwidth (e.g. Cable).
> ISP2 - Slower, reliable, symmetric bandwidth (e.g. T1).
>
> LAN ---- ISP1
> \ /
> ASA
> / \
> DMZ ---- ISP2
>
> I woud like ISP1 one to receive all outgoing LAN traffic (i.e. general
> office Internet traffic).
>
> I would like ISP2 to be used for any incomming connections to the DMZ
> and to maintain our VPNs to remote sites.
>
> In the event ISP1 is down, outgoing LAN traffic would be re-routed to
> ISP2.
>
> In the event ISP2 is down, VPN connections would be re-connected via
> ISP1.
>
> Thanks for any help. I'm just trying to get an idea of what's going
> to be involved in making this type of setup work.



You cannot do all that you want, but some of it.

1, ISP redundancy, yes definately. You need the Sec Plus license. Very easy
to configure.
http://www.cisco.com/en/US/products/...806e880b.shtml

2, Terminations of the VPN to ISP2. Absolutely. Thats simple host based
routing. "route isp2 host <vpn peer1> <gateway>" and applying the crypto map
on ISP2's interface.

3, DMZ traffic. No, cannot do. There is no policy based routing features in
the ASA.

4, VPN failover. Nope, cannot do. You cannot have the same peer on 2
different interfaces nor can you have the same destination subnet on 2
interfaces.


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASA error %ASA-4-402126 "please forward this to Cisco" Tilman Schmidt Cisco 1 10-22-2008 03:54 AM
ASA 5510 log messages %ASA-4-419002: Duplicate TCP SYN Tilman Schmidt Cisco 5 02-18-2008 12:07 PM
IPSec PIX 501 - ASA 5510 -> log flooded with %ASA-4-402116 Tilman Schmidt Cisco 0 01-24-2008 10:49 AM
ASA 5505 as hardware vpn client to PIX 501 or ASA 5505 with network extension mode activated bjorn@kumlait.se Cisco 1 06-17-2007 12:43 PM
WCCP on ASA & traffic between physical interfaces on ASA apsolar@gmail.com Cisco 3 02-15-2007 12:16 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57