Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA - Inbound traffic on backup ISP connection

I have a client that has an ASA5520 that has two internet connections, FIOS and Comcast.  The ASA is configured to failover from the FIOS to the Comcast if the FIOS fails.  This works perfectly fine.  However, I was wondering if VPN and other inbound traffic will come into the secondary connection when it is active.  I think VPN will work inbound when the FIOS connection fails, but I am not sure about the other inbound connections.  I have looked around the forums and Cisco.com for an answer to this question, but cannot find anything definitive.

TIA,

Dan

1 REPLY
Cisco Employee

ASA - Inbound traffic on backup ISP connection

Hi,

No, you will need to add statics on the other link and if possible, either configure DDNs or create two entries on the DNS servers, one with the FIOS and the other with comcast.

For example if you have a Webserver, that device will need to have two public IPs, hence two static translations. That way, if the first link goes down, the client will try to use the other IP and of course will use the secondary link and then the secondary static nat entry will take effect.

Mike

Mike
357
Views
0
Helpful
1
Replies