Solved

Dual ISPs on Cisco ASA 5510

Posted on 2011-03-16
3
969 Views
Last Modified: 2012-05-11
I am trying to set up two ISPs on a Cisco ASA 5510. I have it set up however I cannot get the second ISP to route traffic to my FTP server in the DMZ.
Setup:
interface0 - DMZ
interface1 - Internal Network
interface2 - ISP #1 Primary
interface3 - ISP #2 New

I  can route traffic from ISP 1 to DMZ however when I try to set-up access from ISP 2 to the DMZ it doesn't respond.

I want to allow fixed external users to route either over the first ISP to the ftp server in the DMZ or over the second ISP to the server in the DMZ

Is this possible?
0
Comment
Question by:txdolfan
  • 2
3 Comments
 
LVL 4

Expert Comment

by:LeDaouk
Comment Utility
you have to add the IPS2 gateway to your dynamic NAT rule, and add a static route for ISP2 for outbound trafic but and for inbound trafic you have to add statitc nat rule
0
 

Author Comment

by:txdolfan
Comment Utility
In my static routes I have the following:
Interface | IP Address | NetMask | Gatway IP | Metric
ISP1    0.0.0.0   0.0.0.0   74.7.100.81
inside 192.168.144.0 255.255.255.0  192.168.145.1

The ISP2 gateway is 65.36.78.1 My ISP2 IP is 65.36.78.4 -- Do I put a static route in for the 65.36.78.1 address?


In my DMZ NAT Rules i have translated External IPs pointing to the same IP of the FTP server.

I may be over my head.
0
 
LVL 4

Accepted Solution

by:
LeDaouk earned 500 total points
Comment Utility
yeh create ISP2 0.0.0.0 0.0.0.0 65.36.78.1 with metric 2
and do not forget to add the 65.36.78.1 to the dynamic NAt rule, so you will have in the translated rule inside -> 2 outside
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Policy Base Routing Cisco 6500 Switch 10 71
cisco 800 newbe 4 51
IPv6 Address reservation on Cisco router 3 27
DHCP on ASA 3 20
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now