Cisco ASA - Multiple Inside and Outside Interface WAN Routing

Posted on 2010-01-11
Medium Priority
Last Modified: 2012-08-14
I have a Cisco ASA firewall that's set up with an inside network, dmz network, and two outside networks. We have a track configured for internet failover for the zones outside (primary) and backup (secondary). We are going to be adding a new guest network, and would like that to by default route out the backup interface.

Is this actually possible, or does this qualify as Policy Based Routing? I thought this was possible with a new NAT ID and tweaking the corresponding NAT lines... like

nat (guest) 1
nat (inside) 2
global (backup) 1 interface
nat (outside) 2 interface

Would that work? I don't care about services, just the actual source of the traffic, and they will be completely separate interfaces.
Question by:InterWorks
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
LVL 33

Accepted Solution

MikeKane earned 2000 total points
ID: 26292526
Nope - its not going to work.  This policy based routing is beyond the ASA'a capabilities.  

Author Comment

ID: 26297004
That's very unfortunate.

I'm having trouble figuring out how to do this without the addition of an additional ASA. The inside default gateway is a Cisco Catalyst 3750, and the default route ends up being the ASA. I know I can configure PBR on the 3750, but I'd still end up needing to send the traffic somewhere, back to the ASA.

I made a typo on the above lines, it was supposed to be two nat lines, and two global lines. With a config like above, the NAT should apply, but it would just try to use the wrong addresses (from backup) on the default route (on outside)?

I know an easy fix is to setup PBR on the 3750, and add in a new firewall for that second guest internet line. Is there any way to leverage the existing hardware in my setup? It's more complex than I'm stating, but the details aren't very important.

LVL 33

Expert Comment

ID: 26297692
The issue with the ASA is that you can only have one catch all route for the outside interface.   That is why you can have a failover setup with 2 ISP's but you can't do load balancing.   It's just beyond what the ASA was designed to do.  

Just a thought...   if this is a guest network, does it need to go behind the ASA at all?   you could drop an AP in between the backup ISP link and the ASA to broadcast a wireless AP that would allow for 'guest' connections while, at the same time, not interfering with the ASA's backup ISP config....

Author Comment

ID: 26298321
It's behind the ASA based on the cabling & switch VLAN configuration right now. I think we're just going to toss another, possibly even home class, firewall to serve up that guest network on a different IP address.

Featured Post

Enroll in August's Course of the Month

August's CompTIA IT Fundamentals course includes 19 hours of basic computer principle modules and prepares you for the certification exam. It's free for Premium Members, Team Accounts, and Qualified Experts!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question