Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA 5510 Dual ISP, one routed one NAT

Hello,

I am trying to figure out the proper configuration for ISP failover on my ASA 5510, here is my senario:

Currently our primary ISP link is being provided by a consotium for schools so we have no public ip address on the outside interface of the ASA. The firewall is acting as a router, with no nat function on that link. We wanted to create a failover link to our cable provider which will give us a public ip on the second outside interface of the firewall, and I have it natted to the inside interface. When i set up SLA and the first routed link fails, it fails over to the natted link perfectly and i can see the nat translations. When SLA fails over again to the primary link the nat translations are not removed and internet access breaks until i remove the nat statements and clear xlate. If anybody has insight on this, or a possible workaround, your input will be greatly appreciated as my head hurts from banging it into a wall.

Everyone's tags (5)
5 REPLIES

ASA 5510 Dual ISP, one routed one NAT

Hello Ryan,

What version are you running on the ASA?

What about timeout floating-conn

For more information about Core and Security Networking follow my website at http://laguiadelnetworking.com


Any question contact me at jcarvaja@laguiadelnetworking.com

Cheers,

Julio Carvajal Segura

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com

ASA 5510 Dual ISP, one routed one NAT

you could also try to create an identity NAT instead of NONAT if you are running the older codes 8.2 and below... the difference is that one NATs the IP to itself and the latter bypasses the NAT process completely...

Patrick

New Member

ASA 5510 Dual ISP, one routed one NAT

I believe you need to check your tracking. Not sure how do u track it for your SLA.

Thanks

swap

Bronze

ASA 5510 Dual ISP, one routed one NAT

Hello Ryan,

I would agree with Julio on this one:

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080bc8549.shtml

Regards,

Felipe.

New Member

ASA 5510 Dual ISP, one routed one NAT

Hello Ryan,

Could you please post the configuration for us?

Best

Arun

471
Views
0
Helpful
5
Replies