cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
641
Views
0
Helpful
2
Replies

How to implement two default gateways on ASA5550 pair

jay.anton
Level 1
Level 1

Hi all,

Here's the scenario...

I have two ISPs (L3 and XO) each connected to it's own 3925E.  Currently, I'm only receiving the default route from the ISPs.  We essentially dedicate our L3 connection for Inbound traffic (e.g. Website hosting) and, the XO connection for outbound traffic (e.g. Internet browsing).  We also currently terminate our Cisco VPN clients to a pair of ASA5520s hosted on the XO connection.  We'd like to migrate those clients to a pair of ASA5550s and utilized the L3 connection.  On the ASA5550s, I have an interface on the L3 subnet and an interface on the XO subnet.  But, the default route on this ASA5550 pair points to the 3925E on the XO connection.  The challenge is, how can I terminate Client IPSec tunnels to the L3 interface if the default gateway is pointing to XO.  This asymetric routing will not allow phase I to establish.  I have a feeling I can get around this with policy based routing or, Firewall context...but, looking for ideas at the moment!

Thanks,

Jay

Best of knowledge!       

Best of knowledge!
2 Replies 2

smitty6504
Level 1
Level 1

Jay,

I do not believe that the ASA can do PBR and for the firewall context you will need to make sure you are using 9.x code as anything below 9 is not allowed to do VPN when doing muli-context.

Thanks for the post...great information on the version!

 

Sincerely,

Jay

Best of knowledge!
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: