Solved

2 ISP on 1 PIX with different computers on the same subnet using different ISPs

Posted on 2008-10-21
4
312 Views
Last Modified: 2011-10-19
My office has been running off of a single T-1 line up to this point.  Myself and another tech do a lot of downloading for various pieces of software and a T-1 just isn't enough.  We had a cable line put in so that we can use the cable and everyone else can stick on the T-1.  

Here is the goal.  Have two computers on the 10.1.1.0 subnet (mine and the other tech's) go out through the cable while everything else goes out the T-1.  Failover would also be desired both ways.  I am not sure that both of these are possible at the same time, but I would settle for at least getting myself and the other tech onto the cable for now.

Please see the attached jpg for a topology diagram to help explain the setup.

nettop.jpg
0
Comment
Question by:Telstar-Networks
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 2

Expert Comment

by:JimmyLarsson
ID: 22770616
Hello

This is not possible because the fact that the Pix doesn support multiple default routes.

However, there is a "Dual ISP" functionality in newer versions of pix-software. With this function You can have a spare ISP connected. With a tracking-option the Pix can then sense if the primary ISP connection goes down and then route all traffic to the second ISP instead. But as I sait this is a pure failover-function and also only handles outbound traffic.

More info about the dual-ISP function:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml
0
 
LVL 1

Author Comment

by:Telstar-Networks
ID: 22771074
What would be the minimum I could do in order to accomplish my goal by going outside of the PIX?
0
 
LVL 4

Expert Comment

by:yurisk
ID: 22774906
PIX/ASA do not provide such service, no matter what firmware version. NEwer ASA indeed provide
Dual-ISP functionality but only for complete failover , i.e. when main link goes down back up one kicks in.
Load balancing you want to do is not possible with PIX/ASA , you need  policy routing which  they dont have.
Whatever solution is possible it would be w/o PIX involved. From current diagram I can only suggest
setting up direct connection between your Core router and cable modem then doing policy
routing (if supported) on this COre router.
0
 
LVL 1

Accepted Solution

by:
Telstar-Networks earned 0 total points
ID: 23215218
Yea, just put in a whole other PIX and router.  Thanks for the advice.
0

Featured Post

Get HTML5 Certified

Want to be a web developer? You'll need to know HTML. Prepare for HTML5 certification by enrolling in July's Course of the Month! It's free for Premium Members, Team Accounts, and Qualified Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month9 days, 9 hours left to enroll

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question