Second ISP Circuit

Posted on 2008-11-12
Medium Priority
Last Modified: 2012-05-05
We currently have one main ISP circuit coming into our data center.  It goes to a Catalyst 2950 which is the Internet switch and then to an ASA 5540 and a 6509 that does all layer 3 routing.  A second ISP circuit has been installed for backup purposes and I am trying to decide how best to set it up.  I have an additional ASA 5540 plus extra switches and routers that are not in use and can be used if needed.  I want the internal network to stay the same, just with the ability to flip outbound traffic out the different gateway if needed and also would be setting up additional A records using the new ISP public IPs mapped to our internal servers such as the e-mail server and web server so that if the main circuit goes down, incoming traffic still transparently comes through via the second circuit.

Has anyone done, or is doing this sort of scenario?
Question by:NRL71
LVL 13

Accepted Solution

kdearing earned 750 total points
ID: 22947536

Expert Comment

ID: 22950514
As an idea,

Use a bonder to join the 2 links together, this gives you more bandwidth all the time, and provides fail over in that if one dies the other is still up and running.  
There is a free solution at     http://www.upstreaminter.net/bondedcd.shtml
Have a look and see if it meets your needs?

LVL 28

Assisted Solution

mikebernhardt earned 750 total points
ID: 22952143
The following  comments assume that your 2nd curcuit utilizes a 2nd ISP. If that's not correct please let me know.

Moving outbound traffic out the 2nd gateway is pretty easy. You can do this with floating static routes, HSRP, SAA object tracking, etc.

But your bigger problem is changing DNS records for the inbound traffic you apparently have. Changing DNS records takes not only manual effort, but hours of propagation time. Do you have your own IP address space, or are you using private RFC 1918 addressing, or are you using public address space provided by the first ISP? The only really effective way to manage inbound traffic is to have your own address space that you can advertise to both ISPs via BGP. This is only required for the public-access servers you have but it provides consistent addressing regardless of ISP.

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are times where you would like to have access to information that is only available from a different network. This network could be down the hall, or across country. If each of the network sites have access to the internet, you can create a ne…
If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question