ASA PBR workaround

Jeremy Weisinger
Jeremy Weisinger used Ask the Experts™
ASA has 2 ISP connections. Primary and failover. I'm trying to NAT an IP on the failover connection for SSH traffic to an internal device on the LAN.

I can never bring up the connection and I presume it is just routing it over the primary connection. I see that PBR is available on 9.4 but we're running 9.3 right now.

Is there any workaround for this?

Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Most Valuable Expert 2015

It's not clear whether you are having a PBR problem, a failover problem, or an inability to test an incoming connection on the failover path with the default route directed to the primary provider.

Can you be just a little more detailed with regard to the problem?

(And, there should be a way to correct any of the three).
Pete LongTechnical Consultant

It's a little known fact that if you have two interfaces in 'Standby ISP' on an ASA, You can use the secondary interface for traffic that is sourced from OUTSIDE the ASA.

This would seem to be exactly what you want? But it will only work with a static PAT (port forward) from the secondary interface, to an internal host.


object network Internal_SSH_Server
nat (inside,secondary) static interface service tcp ssh ssh
access-list inbound_secondary permit tcp any object Internal_SSH_Server eq SSH
access-group inbound_secondary in interface secondary

William MurrayNetwork Engineer

I would suggest going to 952-2, it supports PBR.
Senior Network Consultant / Engineer
This has been put on the back burner and will probably address later in the year. Sorry for the delay.
Jeremy WeisingerSenior Network Consultant / Engineer


Been tasked with other things and can no longer work on this issue.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial