Solved

Cisco ASA 5505 different  ISP links with mutual failover possible

Posted on 2011-03-02
4
968 Views
Last Modified: 2012-06-21
Thanks in advance for your assistance.

I have a used Cisco ASA 5505 which has been set to default factory config.

I possess two different ISP links from two different ISPs.

My question is theoretical.

With the latest software version of the ASA and ASDM, I would like to:

1. Inside network to use ISP link #1 as default route to internet

2. DMZ network network to use ISP link #2 as default route to internet

3. Inside network to failover to ISP link #2 using a tracked route

4. DMZ network to failover to ISP link #1 using a tracked route.


Is this even possible? I have the Security Plus license on the box.

If so, is this as simple as configuring the correct global/route statements and the correct tracked route statements (SLA MONITOR) or is this more complicated than that?

Thanks!!!
0
Comment
Question by:rpacint
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 35018664
HI,

It is not possible, ASA not knows policy based routing!
You need a router with 3 ETH leg to do it!

Best regards,
Istvan
0
 
LVL 2

Expert Comment

by:mwblsz
ID: 35019048
I would say no too.
ASA can allow you do simple failover, like you are using conn1 all the time, and only when conn1 is down, you can failover to conn2. But it can not handle the complex scenario you describe. You will need one or two routers and carefully network design to do that.

sincerely
0
 
LVL 16

Accepted Solution

by:
Michael Ortega earned 250 total points
ID: 35036997
Dual WAN failover can only be accomplished on the 5505 with 2 units. You can do active/standby. The failover is not stateful either so all connections through the first link would be lost when failing over.

Here's a simple configuration for setting up 2 x ASA5505's in Active/Standby failover:
http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/

You might consider an 1921 ISR with an extra fast ethernet or gig module. You could do something a simple asa default routes through both links, but your secondary link would have a higher administrative distance.

MO
0
 

Author Closing Comment

by:rpacint
ID: 35039617
Also created a TAC with Cisco. They confirmed this as well. With a single 5505, the device can support only one default route. A router is required to do the task involved.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question