How to implement two default gateways on ASA5550 pair

Unanswered Question

Hi all,

Here's the scenario...

I have two ISPs (L3 and XO) each connected to it's own 3925E.  Currently, I'm only receiving the default route from the ISPs.  We essentially dedicate our L3 connection for Inbound traffic (e.g. Website hosting) and, the XO connection for outbound traffic (e.g. Internet browsing).  We also currently terminate our Cisco VPN clients to a pair of ASA5520s hosted on the XO connection.  We'd like to migrate those clients to a pair of ASA5550s and utilized the L3 connection.  On the ASA5550s, I have an interface on the L3 subnet and an interface on the XO subnet.  But, the default route on this ASA5550 pair points to the 3925E on the XO connection.  The challenge is, how can I terminate Client IPSec tunnels to the L3 interface if the default gateway is pointing to XO.  This asymetric routing will not allow phase I to establish.  I have a feeling I can get around this with policy based routing or, Firewall context...but, looking for ideas at the moment!



Best of knowledge!       

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
smitty6504 Fri, 02/28/2014 - 10:28
User Badges:


I do not believe that the ASA can do PBR and for the firewall context you will need to make sure you are using 9.x code as anything below 9 is not allowed to do VPN when doing muli-context.


This Discussion