Using 2 ISP connections for ASA and VPNs?

Posted on 2011-10-20
Last Modified: 2012-05-12
I was wondering if this configuration would be possible (see attached). I have a location in India that wants to add a second ISP connection for redundancy and to use it for just web traffic. There’s an existing network connection that is there that they want to dedicate to a VPN tunnel back here at HQ. Is this possible? The thought is to add a static route to our VPN appliance at HQ to use the default gateway of the existing fiber connection and we would be a gateway of last resort to use the cable connection’s default gateway. I would have weighted routes so that in the event on of the connections goes down, I would be able to get out using the other connection.

I figured this was not possible without possibly using another ASA to connect the cable connection to and establish two VPN tunnels and use route tracking? Any feed back would be appreciated.

Question by:jbla9028
    LVL 32

    Accepted Solution


    You can definitely have more than one outside interface, outside and outside 2 using the same security level assignment, usually 0.

    As long as they had seperate IP ranges you could route to services based on the unique IPs. The problem may be the return traffic, which interface is choosen? For specific return IP addresses luike a VPN to HQ you can set a route metric to force traffic out a certain interface. The problem will be random IP addreses on the internet, the firewall will route them out your preferred interface.

    The firewall will not like it if traffic comes in once interface and out the other, there will be some challenges but it can work for some of the traffic.

    harbor235 ;}
    LVL 1

    Author Closing Comment

    Thanks. I also confirmed with Cisco. I can't obviously load balance but I can manipulate data via routes.
    LVL 32

    Expert Comment


    Checkin up on a CCIE?   LOL

    good luck,

    harbor235 ;}

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    Suggested Solutions

    Title # Comments Views Activity
    IKEv2 VS  SSTP 4 45
    Traffic monitoring on Tunnel 7 53
    replace module of Catalyst 6509 4 46
    Who Should Be Radius Clients 6 18
    After several days of searching and hunting for limited documentation, I wanted to share this guide to hopefully save someone the hassle of trying to figure this out on their own. I have tested this on Xendesktop 7.1 and PS 4.5 running simultaneous…
    #Citrix #Citrix Policies #XenDesktop #VDI #POC #Citrix Univeral Printer Driver #Citrix UPD
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    731 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now