Firewall outbound failover ok but hot to do the inbound

Unanswered Question
Jan 29th, 2008

Hello,

see the link for ASA reduntant config

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

also read the below.

This configuration provides a relatively inexpensive way to ensure that outbound Internet access remains available to users behind the security appliance. As described in this document, this setup may not be suitable for inbound access to resources behind the security appliance. Advanced networking skills are required to achieve seamless inbound connections

How can we configure the inbound reduntant for the outside users access to the inside servers.

Thanks

swami

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
t.lawton Thu, 01/31/2008 - 14:13

You have a couple of options. First, use a DNS round robin. Have two "A" records for your server,i.e. www.domain.com 192.168.0.1 and www.domain.com 10.1.1.1. I do not recommend this option as it will cause a 50% fail rate on access your server.

Second option, get two routers, an autonomous system number and block of IP address from ARIN and run BGP, between your two ISPs.

Depending on the amount of network traffic, you may be able to get by with a 2800 series ISR.

This is all based on the diagram I see from the link and is very high level. If you have further questions please don't hesitate to ask.

Actions

This Discussion