03-01-2012 05:28 AM - edited 03-07-2019 05:17 AM
Hello,
I'm stock and I am sure it is simple but I can't find it.
I have an ASA5510 from which I am using 3 interfaces.
-One interface have the main internet connection router
-One interface is attache to a switch 3750 and has multiple virtual interface configured on it
-One interface has another internet connection router.
What I am trying to do is to have only one of the Vlan using the second internet connection and not the first one.
My idea was to just have a static route who says that on interface VLAN_B (for the special VLAN), all traffic goes to 2nd internet router interface.
But it does not route.
All I have is a default route configured : on interface Internet1 0.0.0.0/0 goes to 1st internet router interface.
Any idea or help ?
Thank you very much
Solved! Go to Solution.
03-22-2012 05:48 AM
Hi
what i can think of is to run the asa in multiple context mode.
use one context for routing the special vlan and use the other context for routing the rest.
I dont run the asa itsself in multiple context, but i have 2 fwsm' s running in multiple context and by multiple context what you want to do is possible.
You might want to check your reseller if a license is needed though for your asa or if its onboard already.
Good luck.
03-01-2012 06:05 AM
03-22-2012 01:10 AM
Thanks for your answer but I don't see how route map would work here. I am not really familliar wth route map I have to say.
03-22-2012 03:34 AM
Hi,
What he means is something like this:
Example: vlan 10 has to go out to router 2 and vlan 20 has to go out to router 1
For instance:
vlan 10 = 10.1.1.0 /24
vlan 20 = 10.1.2.0/24
Create ACL to match address ranges
access-list 101 permit ip 10.1.1.0 0.0.0.255 any
access-list 102 permit ip 10.1.2.0 0.0.0.255 any
Create route-map, match address 101 and set next-hop to router 2
route-map outbound permit 10
match ip address 101
set ip next-hop
Create route-map, match address 102 and set next-hop to router 1
route-map outbound permit 20
match ip address 102
set ip next-hop
Apply route-map
interface Ethernet0/x
ip policy route-map outbound
interface Ethernet0/y
ip policy route-map outbound
Now when a packet enters ethernet0/x and its source ip = 10.1.1.x, a next hop to router 2 will be set. etc.
03-22-2012 04:05 AM
Thanks a lot for your answer, it makes it more clear. But one problem is still there, I am configuring that on my ASA 5510, and there is no "set ip next-hop" only set ip metric/metric-type
03-22-2012 04:10 AM
Do you think that by configuring OSPF I would be able to isolate the 2 connections ?
I mean if I put vlan 10 and router 1 in one OSPF process and Vlan 20 and router 2 in another OSPF process, would it allow me to apply kind of 2 different default gatway (one per process) ?
03-22-2012 04:33 AM
Hi
not sure, but i dont think so.
i m now logged in a asa here and will check some stuff.
ps. I did see that its indeed not possible to configure the next hop.
03-22-2012 05:48 AM
Hi
what i can think of is to run the asa in multiple context mode.
use one context for routing the special vlan and use the other context for routing the rest.
I dont run the asa itsself in multiple context, but i have 2 fwsm' s running in multiple context and by multiple context what you want to do is possible.
You might want to check your reseller if a license is needed though for your asa or if its onboard already.
Good luck.
03-22-2012 05:50 AM
Thanks a lot for the search. I look into the multiple context mode.
03-22-2012 07:54 AM
Thanks A LOT Ton V Engelen.
I had already the good license for the multiple context and now it is working like a charm
03-22-2012 08:04 AM
Hi
very cool!
And you worked this config change out very fast!!!
Thanks!!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: