[Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

redundancy on cisco asa

Posted on 2014-01-28
7
Medium Priority
?
301 Views
Last Modified: 2014-02-14
Hi Guys,

I have two ISPs and I was wondering could i use an interface for each ISP and set one to primary and set one to secondary??

So, if the primary went down traffic could go out on the 2nd one?
0
Comment
Question by:jonathanduane2010
7 Comments
 
LVL 12

Expert Comment

by:Infamus
ID: 39814830
add two different default route.

For example, if ISP1 10.1.1.1 and ISP2 172.20.1.1

ip route 0.0.0.0 0.0.0.0 10.1.1.1
ip route 0.0.0.0 0.0.0.0 172.20.1.1 10

you can also use object tracking....
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39814871
Are you using this for outbound traffic only?

Or are you hosting services that require inbound access?
0
 

Author Comment

by:jonathanduane2010
ID: 39814903
no, it would be for emergencies only really, so outbound traffic would be all we need....
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 57

Accepted Solution

by:
giltjr earned 1840 total points
ID: 39814939
Then using object tracking with SLA and changing the default route.

Replace 1.1.1.1 with the IP address of ISP#1 router and 2.2.2.2 with the IP address of ISP#2's router.


route outside 0.0.0.0 0.0.0.0 1.1.1.1 1 track 1
route backup 0.0.0.0 0.0.0.0 2.2.2.2 254

sla monitor 1
type echo protocol ipIcmpEcho 1.1.1.1 interface outside
num-packets 3
frequency 10

sla monitor schedule 1 life forever start-time now

track 1 rt 1 reachability

Ref:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml
0
 

Author Comment

by:jonathanduane2010
ID: 39815029
great thank you!

I am using the ASDM launcher, can i input these commands through the CLI ?
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39815122
Yes or you can scroll down some on the above link, I'm fairly sure that it shows how to do it via the ASDM.
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 39815430
Don't forget you will need a sec plus licence!
Cisco ASA/PIX 8.x: Redundant or Backup ISP




Pete
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…

865 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question