Solved

Second ISP connection on our  Cisco ASA 5550

Posted on 2009-04-06
6
625 Views
Last Modified: 2012-05-06
We have a Cisco ASA 5550. We currently have one T1  line , but want to add a Cablemodem line with Static IP's to help speed up things.  Would there be anyway of making all outgoing trafic ( which is mostly internet access) to thorugh the cable modem.If the Cablemodem line goes out then we should automaticly switch to the T1. Also, for incomming traffic, we would like to use the T1 primerly and if there is to much incomming trafic on the T1 then we also would like some of that trafic to thourgh the Cablemodem.. Also, if the T1 goes out incomming trafic should go thought the cable modem. Not sure if we can even do that since we have a lot of Nets on the incoming interface (T1).

Someone suggested that we use OSPF.Not sure how that works or is the righ thing to do.
FYI, we have two of our branch office connedted to the main site ( asa5550) via VPN.

0
Comment
Question by:netcomp
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 23

Expert Comment

by:debuggerau
ID: 24084000
wouldn't least cost routing help, that way, you could set the cable up as least cost, and when it was unavailable, switch over to T1...

However, unless you are prepared to modify DNS records, how are you going to publish the other IP for incoming?

OSPF, open shortest path first, so it is speed & availability mainly. Only the internet points wont be running it, it needs to be contained within your PIX...
0
 
LVL 33

Expert Comment

by:MikeKane
ID: 24087964
The ASAs do not route traffic to multiple ISPs at once.   The ASA will support multiple incoming Internet connections, but only for backup if the primary line goes down.     The ASA will not route traffic based on load either.      

This link from cisco explains the process for setting up 2 ISP connections for a failover scenario.  
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

To do this, you will need a Security PLUS license on the firewall.    

Hope that helps.

0
 
LVL 1

Author Comment

by:netcomp
ID: 24097995
So , I guess you are saying that I would need a Cisco Router to do load balancing on two different ISP's.?? ?

Also,  I did not see any notes the " security PLUS License " that you mentioned above in the link. Are you saying that I need that to route outgoing traffic to the new ISP. How do I do add the license and how to I buy it??
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
ID: 24100280
A SHOW VER on the firewall displays the lic. info.    If you don't have it, contact a local cisco reseller for pricing.  

And yes, you would need another device to load balance between 2 ISP's.   That functionality is beyond what the ASA is designed to do.  

0
 
LVL 1

Author Comment

by:netcomp
ID: 24103275
Which router do you think I should be looking at   and would the router sit in front of the ASA or behind it. Thank you Mike,
0
 
LVL 33

Expert Comment

by:MikeKane
ID: 24107247
That's not really a question I can answer just from the few lines of description we have here.    There are quite a few balancers on the market. You can go with free opensource all the way up to $100,000.    You would need to take a look at budget (obviously) along with total number of targets for balancing, throughput, total connections, service level, etc....     Its really up to  you to take a look at what you need, then begin contacting vendors or resellers and start getting some details on the product you would like.  Many times, VARs can supply the expertise if needed.
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Powerful tools can do wonders, but only in the right hands.  Nowhere is this more obvious than with the cloud.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question