• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 412
  • Last Modified:

CISCO ASA 5510 and 2 ISP's

Hi ALL

I have a Cisco 5510 with 2 DMZ interfaces and an outside & inside interface also. The outside interface is connected to our internet router interface, another interface is connected to our ISP.The ASA is configured to NAT translate IP addresses on the  DMZ to configured public addresses from our current ISP. We are due to migrate to a ISP with 6 times the bandwidth the second ISP is connected to another interface on the internet router.

The question I ask is would it be possible as part of a migration process to be able to configure  the ASA with the second ISP's public addresses also so that I can systematically move DMZ devices from the old ISP to the new ISP public addresses one at a time ???

Thanks
0
s1mwat
Asked:
s1mwat
  • 2
1 Solution
 
Garry GlendownConsulting and Network/Security SpecialistCommented:
Configuring another external interface for the connection to the new ISP shouldn't be the problem, but routing most likely is ... as the ASA does not support "clean" PBR, it might be difficult to keep the devices reachable ... or rather, keep the answers going back out the right interface ... setting outgoing routes to one interface or the other will work, but for allowing remote access to DMZ devices you'd need to keep remote IPs reachable on either interface, depending on the target of the communication ...
0
 
s1mwatAuthor Commented:
Thanks, I presume also that I cannot place a secondary address on the outside interface so that the Internet router can deal with PBR ??
0
 
Garry GlendownConsulting and Network/Security SpecialistCommented:
You don't need a secondary on the outside, you can just route the net through the ASA ... should work just fine ...
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now