• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 981
  • Last Modified:

Cisco ASA redundant Link Configuration

I'm trying to configure redundant ISP link on Cisco ASA 5505 following below link.

Internet is working fine from inside to outside but i need to configure web mail access for my external users & still external users need to have VPN access.

Any suggestion on how this can be configured so VPN & webmail access works when primary link is down.
1 Solution
Pete LongTechnical ConsultantCommented:
>>Any suggestion on how this can be configured so VPN & webmail access works when primary link is down.

With network redundancy you cant do this you would need to deploy the firewalls in fail over http://www.petenetlive.com/KB/Article/0000048.htm
The problem is that those services are tied to a specific IP number.  The VPN endpoints are IP specific, as is the URL to access Webmail.  The short answer is that the cheapest/easiest way to do this is manual.  Host your DNS with a provider that makes changes quickly, and manually update your webmail URL to point to the failover IP if your primary ISP is down.  As for remote-client VPN, if using Cisco VPN client, it has a Backup option in the client where you can configure the failover IP number, but you'd have to configure the firewall to listen for dynamic VPN tunnels on both ISP interfaces.

The longer answer is BGP.  Obtain a /24 from an ISP, get another ISP to agree to BGP for that IP block, set them both up to BGP advertise that IP block, then configure your firewall to only use that IP block and direct traffic to an upstream router that handles the BGP sessions.  That way your Internet IP number doesn't change with whichever ISP is down.

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now