Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA/PIX Redundant Tunnels with Separate Interfaces and ISPs?

I have an ASA5510 at location 1, and a PIX at location 2. Location #2's PIX is on a multihomed BGP routing setup, so it's primarily covered for any issues.

Location 1 has 2 internet lines but each is routed independently and thus not multihomed. Can I take the ASA5510 and define 2 interfaces, one to each ISP, and designate one as the backup? Both would talk back to the Site #2 PIX. Is it possible to apply a crypto map like this? How do I deal with default gateway routing issues?

This is rather complicated for me.


Re: ASA/PIX Redundant Tunnels with Separate Interfaces and ISPs?

V7.2(1) has "Standby ISP Support - This feature allows you to configure a link standby ISP if the link to your primary ISP fails. It uses static routing and object tracking to determine the availability of the primary route and to activate the secondary route when the primary route fails." See the Release Notes ( and CLI Config Guide.

I think VPNs would drop and need to be re-established. The PIX at site#2 would need two peers IPs for the ASA configured in the crypto map

New Member

Re: ASA/PIX Redundant Tunnels with Separate Interfaces and ISPs?

Fantastic! I was unaware of the new feature. I will investigate.

It wouldn't surprise me either if the VPN tunnel dropped and need to be restablished. Thanks!