txdolfan
asked on
Dual ISPs on Cisco ASA 5510
I am trying to set up two ISPs on a Cisco ASA 5510. I have it set up however I cannot get the second ISP to route traffic to my FTP server in the DMZ.
Setup:
interface0 - DMZ
interface1 - Internal Network
interface2 - ISP #1 Primary
interface3 - ISP #2 New
I can route traffic from ISP 1 to DMZ however when I try to set-up access from ISP 2 to the DMZ it doesn't respond.
I want to allow fixed external users to route either over the first ISP to the ftp server in the DMZ or over the second ISP to the server in the DMZ
Is this possible?
Setup:
interface0 - DMZ
interface1 - Internal Network
interface2 - ISP #1 Primary
interface3 - ISP #2 New
I can route traffic from ISP 1 to DMZ however when I try to set-up access from ISP 2 to the DMZ it doesn't respond.
I want to allow fixed external users to route either over the first ISP to the ftp server in the DMZ or over the second ISP to the server in the DMZ
Is this possible?
you have to add the IPS2 gateway to your dynamic NAT rule, and add a static route for ISP2 for outbound trafic but and for inbound trafic you have to add statitc nat rule
ASKER
In my static routes I have the following:
Interface | IP Address | NetMask | Gatway IP | Metric
ISP1 0.0.0.0 0.0.0.0 74.7.100.81
inside 192.168.144.0 255.255.255.0 192.168.145.1
The ISP2 gateway is 65.36.78.1 My ISP2 IP is 65.36.78.4 -- Do I put a static route in for the 65.36.78.1 address?
In my DMZ NAT Rules i have translated External IPs pointing to the same IP of the FTP server.
I may be over my head.
Interface | IP Address | NetMask | Gatway IP | Metric
ISP1 0.0.0.0 0.0.0.0 74.7.100.81
inside 192.168.144.0 255.255.255.0 192.168.145.1
The ISP2 gateway is 65.36.78.1 My ISP2 IP is 65.36.78.4 -- Do I put a static route in for the 65.36.78.1 address?
In my DMZ NAT Rules i have translated External IPs pointing to the same IP of the FTP server.
I may be over my head.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.