Multiple Internet connections with Cisco ASA

Posted on 2008-02-06
Medium Priority
Last Modified: 2012-06-27
We have multiple buildings all terminating at one location.   I currently have a Cisco ASA 5510 which filters traffic to our external router and T-1 line.  We have a cable modem line that I'd like to utilize as we're starting to fill up the pipe on our T-1.  Ideally I would like to filter traffic by buildings.  Is there a way for me to break traffic out by subnet and send all traffic from one particular building over the cable modem and have all other traffic go out over the T-1? If so, can you provide me with some help in configuring this?  

Question by:erndog5800
  • 2

Expert Comment

ID: 20836637
what do you have in the outside network fo the ASA?  

you should be able to route the traffic out the outside interface by subnet to either the T1 of cable.

Author Comment

ID: 20836733
I'm not sure if I understand the question.  This ASA is on the edge of our network, so currently it is set up as ASA -> Router -> T-1 -> Internet.  I was hoping to bypass the router completely and connect an interface of the ASA directly to the cable modem.    So, to clarify, four of my buildings would continue to go out through the firewall-> router ->T-1 -> Internet. While one building would go out through firewall -> Cable Modem -> Internet.  
LVL 28

Accepted Solution

batry_boy earned 2000 total points
ID: 20837125
You can't do what you're wanting to do with the ASA alone.  I think what you are looking for is called Policy Based Routing (PBR).  Read through the following document and see if this fits your scenario.


Specifically in that document, read the first benefit under the section named "The Benefits of Policy-Based Routing".

If you use this, you'll implement PBR on your internal network router (the one that is called "Cisco-1 Router" in the following URL):


Author Comment

ID: 21257218
According to our outside support folks, it Looks like we need another piece of hardware in the mix to support multiple connections.  I was hoping to slap something together on the cheap to take advantage of available connectivity, but it looks like we'll have to invest a bit to get this functionality.


Featured Post

KuppingerCole Reviews AlgoSec in Executive Report

Leading analyst firm, KuppingerCole reviews AlgoSec's Security Policy Management Solution, and the security challenges faced by companies today in their Executive View report.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
How to fix display issue, screen flickering issue when I plug in power cord to the machine. Before I start explaining the solution lets check out once the issue how it looks like after I connect the power cord. most of you also have faced this…

601 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question