ASA Policy Based Routing alternative

Unanswered Question
Feb 17th, 2009

Guys,

I want to divert the traffic originating from E3(Server Farm) to E2 using some kind of route-map/PBR but found out that ASA doesnt support this. Is there any other way to accomplish this?

Thanks,

Chad

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (3 ratings)
Loading.
Renato Morais Thu, 12/16/2010 - 07:09

The ASA can perform Service Based Routing, but not source routing. For example, if you want to forward the outbound SMTP traffic through a secondary ISP:

route outside 0.0.0.0 0.0.0.0 192.0.2.254 1
route out-backup 0.0.0.0 0.0.0.0 172.16.0.254 2
nat (inside) 1 0.0.0.0 0.0.0.0
global (outside) 1 interface
global (out-backup) 1 interface
static (out-backup,inside) tcp 0.0.0.0 smtp 0.0.0.0 smtp netmask 0.0.0.0

The static statement forces any SMTP traffic to be forwarded through the secondary ISP,  even with the default route pointing to the ISP1 gateway.

Federico Coto F... Thu, 12/16/2010 - 07:22

Renato,

This is very clever I had no idea about that!

I give you +5 for it!! and thank you very much ;p

Federico.

Actions

This Discussion