Solved

CISCO Static Routing

Posted on 2014-09-25
9
361 Views
Last Modified: 2014-09-26
Hi,

We have CISCO ASA 3750 L3 Switch and we want to do load balancing across to Internet lines.  The issue that I have is that we have 1-to1 NATs for some of our devices on the network and I know that we cannot have them go out both Internet lines

How can I create a static route to the firewall that has the NAT policies for those devices

for example:

device 192.168.1.1 needs its routes of last resort to go to 192.168.72.253

Thank you in advance
0
Comment
Question by:thomasm1948
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
9 Comments
 

Author Comment

by:thomasm1948
ID: 40344029
would something like this work and still allow the device to all of my other VLANS

access-list 1 permit 192.168.1.1

route-map NatGwy permit 1
set up next-hop 192.168.72.253

ip policy route-map NatGwy

I am not sure but I think policy based routing might work.  any ideas?
0
 

Author Comment

by:thomasm1948
ID: 40344114
After reading I think I might have to do this , but I am unsure

access-list 1 deny ip host 192.168.1.1 192.168.72.254 255.255.255.255 (new router gateway)
access-list 1 permit 192.168.1.1 any (allowing the host to have access to the other VLANs

 route-map NatGwy permit 1
 set up next-hop 192.168.72.253 (original gateway with the NAT policies)

 ip policy route-map NatGwy

Still unsure though
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 40344280
The ASA doesn't do PBR; only redundant links/routing.

The 3750 doesn't do NAT.

Either way, you probably won't get what you want unless you use a proper router upstream from the ASA on the outside.
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 

Author Comment

by:thomasm1948
ID: 40344601
Hi,

Sorry used some wrong terminology.  The 3750 is our core L3 switch in which currently the last resort route goes to 0.0.0.0 0.0.0.0 192.168.72.253

We got a new Internet line in and the school would like to load balance between them.  The issue that I see is there is static NAT policies on their Pix firewall.  If I do load balancing then those devices such a web portal is not going to work correctly being that the traffic could possibly go out the new pix firewall
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 40344645
Ok, so load balancing is easy.  Just configure a second static route on the 3750 pointing to the new gateway and use the same metric.

You're right - static NAT will be a problem.  Where is your web portal?  Is it on your LAN but accessible from the internet?  If so, that's not going to work too well.  You will only be able to send that portal's traffic through one line at a time or it will break traffic, especially if it runs HTTPS.
0
 

Author Comment

by:thomasm1948
ID: 40344715
How can I route a single device through only one line and then have the rest do load balancing on the 3750.
0
 

Author Comment

by:thomasm1948
ID: 40344719
The web portal is on the LAN and is accessible for the teacher and students outside of the network
0
 
LVL 46

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 40344761
0
 

Author Comment

by:thomasm1948
ID: 40344780
does the 3750 support that.  If so would my idea above work then
0

Featured Post

Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA 5506 blocks telnet 11 61
2950 switch not prompting username and password 4 74
Change SSH password on Cisco 4331 ISR 4 52
Cisco Switch slow_Faulty Link 7 54
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question