Solved

Traffic redirection with ASA 5510

Posted on 2008-10-01
5
1,317 Views
Last Modified: 2009-12-16
I'm trying to find out if it's possible to do traffic redirection with an ASA 5510.

I basically want to say redirect All HTTP traffic going to site X to site A.

Possible?
0
Comment
Question by:condorcape
  • 3
  • 2
5 Comments
 
LVL 32

Accepted Solution

by:
harbor235 earned 125 total points
Comment Utility


Not possible, you need a geographical load balancer. There are some other things you could do with DNS but it requires changing the url;

i.e www.mydomain.com  (site1)
     www.mydomain2.com (site2)

harbor235 ;}
0
 

Author Comment

by:condorcape
Comment Utility
I know you can do things like that with squid.

http://ex-parrot.com/~pete/upside-down-ternet.html :)

I basically want to redirect all traffic that goes to facebook to an error message running on one of our internal servers.
0
 

Author Comment

by:condorcape
Comment Utility
I mean iptables*

I'm basically looking for the equivalent of this command;

/sbin/iptables -A PREROUTING -s 192.168.0.0/255.255.255.0 -p tcp -j DNAT --to-destination 64.111.96.38
0
 
LVL 32

Expert Comment

by:harbor235
Comment Utility


That would be redirection from outside to inisde, i think he means to redirect to a differnet site all together, am i correct in assuming this? if its just port redirection outside to inside then yes the asa can do that.

harbor235 ;}
0
 

Author Comment

by:condorcape
Comment Utility
I think it needs to be done on the proxy :(

Next step is getting WCCP & squid to work.

Thanks for the help!
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
So, you're experiencing issues on your network and you've decided that you need to perform some tests to determine whether your cabling is good.  You're likely thinking that you may need to spend money which you probably don't have on hiring/purchas…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now