Redundant Internet connection through MPLS

See diagram

If SITE A's ISP is down, we would like to use the internet through the MPLS in Site B

I thought of using route ip sla method, but router A does not have the license to do so. Router B and the ASA can track routes in this manner.

RIP is advertised from site B through the MPLS and Router B gets its routes from RIP. Router A is not currently using RIP.

Can RIP be used in this situation? For example, under normal conditions, the default GW in site A is the firewall. If the ISP's gateway becomes unreachable, then IP SLA detects this, then the firewall changes its default gateway towards Site B. Then RIP changes the default GW for router A and B.

Is this a possible solution? Else, can another method be used in this scenario to accomplish what I am trying to do?

Thank you.  Network Diagram
Who is Participating?
John MeggersNetwork ArchitectCommented:
You will want a dynamic protocol on A, otherwise nothing will change in the routing table regardless of what happens with the ISPs.  You will also want each ASA to advertise a default into the internal network.

The ASAs do route tracking (see but you probably only want to track reachability to the next hop from each of the ASAs.  The MPLS cloud would have to pass a default route, which will mean either BGP or a GRE tunnel, neither of which the ASA does, so you would need to add a real router at site B.  If that's working properly, inside routers will receive default routes from each of the ASAs and if one ISP becomes unreachable, that ASA will stop advertising that default route and traffic will take the other path.

One place where you may run into problems is if hosts are using the ASA as their default gateway, I'm pretty sure the ASA will not redirect traffic off that inside interface to get to the firewall.  If that's the case, you may need to point the hosts to a router in the middle that can direct traffic either way based on what's in the routing table.
inf2300Author Commented:

The MPLS is managed by the ISP. I think they are running BGP  and redistributes our RIP.

There is a router in site B but I did not include it in the design. The client's default GW in both networks is the router (not the ASAs).

So, given this information, if both ASA advertises the default route and does route tracking, that would be a possible solution?

Also, if this works, how do you tell the network to "stop broadcasting" the default route since my guess is that the mpls should not advertise it?
John MeggersNetwork ArchitectCommented:
The "stop broadcasting" should happen with the ASA withdraws the default route it was advertising.
Become an IT Security Management Expert

In today’s fast-paced, digitally transformed world of business, the need to protect network data and ensure cloud privacy has never been greater. With a B.S. in Network Operations and Security, you can get the credentials it takes to become an IT security management expert.

inf2300Author Commented:
Yes but how do you manage one default route at each site (so 2) and only one default route for both sites when the isp goes down?

If both sites advertises a default route, where does the "cutoff" happen so that the other site doesnt get that route? (but does when the failure occurs)

Sorry if I am being vague, do not hesitate do ask me questions if things are unclear

John MeggersNetwork ArchitectCommented:
If I'm understanding your question correctly, the "cutoff" will be based on the costs associated with a particular path; when the cost becomes less (or the only option) for sending traffic the other direction, the router will send it that direction.  Metrics will be based, at least in part, on the number of hops, the speed of links, how "loaded" the link is, etc., but you can assign those parameters to influence the decision.  Assuming no other parameters such as policy-based routing, traffic engineering, etc., routers will always choose the lowest-cost path.

So in your case, my recommendation would be to ensure the MPLS cloud is a higher-cost path.  In that case, router A will receive a DR from its local ASA but will also receive a DR from the other side, but that other DR will have a higher cost, so it will be viewed as less preferable.  But if the local ASA withdraws its DR (stops advertising it) because its route tracking is telling it the connection to the ISP is down, then the only DR Router A will receive will be from the other side of the network, and it will take that path regardless of cost because at that point it's the only game in town.  How you do this depends on what routing protocol you're using.  RIP is going to be less effective than OSPF or EIGRP for this because RIP's metric is based solely on hop count, whereas with OSPF and EIGRP you can assign costs to interfaces.  Not really knowing anything else about your network, I would probably use EIGRP because I think it's the easiest to configure.  But OSPF would work as well and if you have non-Cisco devices, or if you're running 7.x code on your ASAs you will need to use OSPF.
inf2300Author Commented:
QlemoBatchelor, Developer and EE Topic AdvisorCommented:
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.