cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
776
Views
0
Helpful
2
Replies

Dual ISP links and SLA on ASA 5505-50

pedro.augusto
Level 1
Level 1

I have two Internet links:

  • ISP1: only Site 2 Site VPNs
  • ISP2: only HTTP/HTTPS traffic and incoming remote access VPNs

With the security plus license I could correctly configure them both as active at the same time on the same ASA device. Also, I've successfully accomplished the following traffic separation:

  • Site to Site VPNs goes out through ISP1
  • HTTP/HTTPS traffic goes out through ISP2

The customer request is that, when ISP1 fails the S2S traffic is relayed through ISP2 -> This is working fine, I've already tested!

But when ISP1's service is restored and that link is working fine, I want that the S2S VPN traffic gets relayed through it again automatically, which didn't happen. My question is: using SLA will the S2S traffic be relayed through ISP1 again automatically when it's services are restored? If not, which technology should I use to accomplish this?

PS: This is all configured on only 1 ASA 5505 whose license was upgraded.

Thanks in advance for any help!

2 Replies 2

pedro.augusto
Level 1
Level 1

So, no ideas about this? Anything?

Hello Pedro,

Can you post your SLA configuration ,tracking configuration with the routing configuration as well, you can change the IP addresses for security purposes.

Regards,

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: