Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Internet Fail-over


I need someone to help me out on finding solution. Let me explain my network scenario.. I have a core switch connecting to internet ASA and MPLS router.

My primary internet route is through ASA(using default route). When internet circuit goes down i have to remove default router towards ASA and route it through MPLS router so that internet could work over MPLS through my hub site internet connection. But i want to remove this manual failover & i want to configure this in the way if my primary internet goes down, internet traffic automatic get routed towards MPLS router. I tried this configuring track but it is not going to work as which ip should track monitor. Internet SP end router ip still be reachable when internet circuit goes down, only connectivity over internet become unreachable.

Pls help here.


Hall of Fame Super Silver

Internet Fail-over

I do not understand your explanation of why using track did not work. Assuming that you are not running a dynamic routing protocol through the ASA I do not know of any way to automate the failover other than track. It should be possible to configure track, to assure that the tracking packets are only forwarded to the ASA, and to detect when the Internet link through the ASA is not working.



Re:Internet Fail-over


How using tracking? Are you incorperating ip sla also?

Can you post your tracking config

Sent from Cisco Technical Support Android App

Please don't forget to rate any posts that have been helpful. Thanks.
New Member

Re: Internet Fail-over

You're missing one thing. You need to add a static host route for the ip you're tracking to alway point it out your internet primary path

Sent from Cisco Technical Support iPad App

New Member

Re: Internet Fail-over

Hi Anukalp,

I understand what you are trying to achieve here. I've deployed this internet failover using ip sla many times. Here's your configuration template:


ip route 'ASA GW' 1 track 1

ip route 'MPLS RTR GW' 10

ip sla 100

icmp-echo source-interface 'Interface connected to ASA'

frequency 10

ip sla schedule 100 life forever start-time now

track 1 rtr 100 reachability

-Verify your IP SLA-

show ip sla statisctics 100

Your primary default route with AD 1 will track 1 that's checking your IP SLA 100 reachability. When (Google DNS) is unreachable, your primary default route will be replaced with your secondary default route.

Hope this helps.


CreatePlease login to create content