Solved

Second ISP connection on our  Cisco ASA 5550

Posted on 2009-04-06
6
619 Views
Last Modified: 2012-05-06
We have a Cisco ASA 5550. We currently have one T1  line , but want to add a Cablemodem line with Static IP's to help speed up things.  Would there be anyway of making all outgoing trafic ( which is mostly internet access) to thorugh the cable modem.If the Cablemodem line goes out then we should automaticly switch to the T1. Also, for incomming traffic, we would like to use the T1 primerly and if there is to much incomming trafic on the T1 then we also would like some of that trafic to thourgh the Cablemodem.. Also, if the T1 goes out incomming trafic should go thought the cable modem. Not sure if we can even do that since we have a lot of Nets on the incoming interface (T1).

Someone suggested that we use OSPF.Not sure how that works or is the righ thing to do.
FYI, we have two of our branch office connedted to the main site ( asa5550) via VPN.

0
Comment
Question by:netcomp
  • 3
  • 2
6 Comments
 
LVL 23

Expert Comment

by:debuggerau
ID: 24084000
wouldn't least cost routing help, that way, you could set the cable up as least cost, and when it was unavailable, switch over to T1...

However, unless you are prepared to modify DNS records, how are you going to publish the other IP for incoming?

OSPF, open shortest path first, so it is speed & availability mainly. Only the internet points wont be running it, it needs to be contained within your PIX...
0
 
LVL 33

Expert Comment

by:MikeKane
ID: 24087964
The ASAs do not route traffic to multiple ISPs at once.   The ASA will support multiple incoming Internet connections, but only for backup if the primary line goes down.     The ASA will not route traffic based on load either.      

This link from cisco explains the process for setting up 2 ISP connections for a failover scenario.  
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

To do this, you will need a Security PLUS license on the firewall.    

Hope that helps.

0
 
LVL 1

Author Comment

by:netcomp
ID: 24097995
So , I guess you are saying that I would need a Cisco Router to do load balancing on two different ISP's.?? ?

Also,  I did not see any notes the " security PLUS License " that you mentioned above in the link. Are you saying that I need that to route outgoing traffic to the new ISP. How do I do add the license and how to I buy it??
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
ID: 24100280
A SHOW VER on the firewall displays the lic. info.    If you don't have it, contact a local cisco reseller for pricing.  

And yes, you would need another device to load balance between 2 ISP's.   That functionality is beyond what the ASA is designed to do.  

0
 
LVL 1

Author Comment

by:netcomp
ID: 24103275
Which router do you think I should be looking at   and would the router sit in front of the ASA or behind it. Thank you Mike,
0
 
LVL 33

Expert Comment

by:MikeKane
ID: 24107247
That's not really a question I can answer just from the few lines of description we have here.    There are quite a few balancers on the market. You can go with free opensource all the way up to $100,000.    You would need to take a look at budget (obviously) along with total number of targets for balancing, throughput, total connections, service level, etc....     Its really up to  you to take a look at what you need, then begin contacting vendors or resellers and start getting some details on the product you would like.  Many times, VARs can supply the expertise if needed.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
clear arp 1 30
Open Port Forwarding but still can't connect RDP 9 50
ASA configuration 2 30
ASA Tunnel 18 35
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question