• No results found

ASA/PIX: Load balancing between two ISP - options

N/A
N/A
Protected

Academic year: 2021

Share "ASA/PIX: Load balancing between two ISP - options"

Copied!
5
0
0

Loading.... (view fulltext now)

Full text

(1)

options

• Is it possible to load balance between two ISP links? on page 1

• Does the ASA support PBR (Policy Based Routing)? on page 1

What other options do we have? on page 1

• SLA Route Tracking on page 1

• PBR on the router outside the firewall on page 2

• Allowing outbound via ISP1 and inbound via ISP2 on page 4

• Multiple context mode on page 5

Is it possible to load balance between two ISP

links?

Presently it is not possible to load balance traffic between two ISP links on an ASA. The reason being, there can only be one default route configured on the ASA.

Does the ASA support PBR (Policy Based

Routing)?

No, the ASA does not support PBR.

What other options do we have?

SLA Route Tracking

(2)

Refer this link: http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/ products_configuration_example09186a00806e880b.shtml

PBR on the router outside the firewall

With this method we can configure both the ISP links on the router outside the firewall. We can translate some traffic to use Primary ISP provided IP address and the rest of the traffic to use Secondary ISP provided IP address. Now, based on this source address that hits the router, we can configure the router to do policy based routing and route the traffic either via the Primary ISP or via the Secondary ISP.

Let us assume the requirement as below:

1. We would like all the users traffic translated to the ISP1 provided address 2. We would like all the servers traffic translated to the ISP2 provided address

(3)

ISP1 provided address block is 10.10.10.0/24 and ISP2 provided address block is

172.18.124.0/24. These are not routable addresses. For simplicity reasons we are using RFC 1918 address space.

ASA config:

Translation for all users to take ISP 1 nat (inside) 1 192.168.2.0 255.255.255.0 global (outside) 1 10.10.10.1

Translation for web and e-mail servers to take ISP2

static (inside,outside) 172.18.124.20 192.168.2.20 netmask 255.255.255.255 static (inside,outside) 172.18.124.30 192.168.2.30 netmask 255.255.255.255

route outside 0 0 172.16.12.2

Router config:

ip access-list ext isp1-addr

permit ip 10.10.10.0 0.0.0.255 any

ip access-list ext ips2-addr

permit ip 172.18.124.0 0.0.0.255 any

(4)

route-map ISP permit 20 match ip address isp2-addr set ip next-hop 172.18.124.2

int f0/0

ip address 172.16.12.2 255.255.255.0 ip policy route-map ISP in

Allowing outbound via ISP1 and inbound via ISP2

Let us take the same example above. We can use one ISP1 for all outbound connections and use IPS2 for all inbound connections.

Translation for all outbound connections from users and servers to take ISP 1 nat (inside) 1 192.168.2.0 255.255.255.0

global (ISP1) 1 10.10.10.1 route ISP1 0 0 10.10.10.254

Here are the translations for inbound connections to the servers: Translation for web and e-mail servers to take ISP2

(5)

In the previous case even the out bound connections made by the servers would take the ISP2 path but, in this example outbound connections from the web and e-mail servers will take ISP1. ONLY the INBOUND connections will come through ISP2 and will be responded back using ISP2.

Multiple context mode

The last option is to use multiple context mode where we can load balance on a per context basis. VPN is not supported in this mode and so are dynamic routing protocols. Please refer this link for the limitations: http://www.cisco.com/en/US/docs/security/asa/asa82/ configuration/guide/contexts.html#wp1146747

References

Related documents

The empirical results show that loan to toal assets, total equity to total assets, loan loss provision to total loan have positive effect on profitability, while

When instead κ ≥ κ w , surrender benefits are less valuable relative to death and survival benefits, but the increase in value for the stopped contract (induced by higher

4) IOS-XR 64 bit Mgmt Network boot using local settings (iPXE) 5) IOS-XR 64 bit Internal network boot from RSP/RP.. 6) IOS-XR 64 bit Local boot using embedded USB media 7) IOS-XR 64

The following discussion focuses on three central developments that have affected the organisation of medical support for British Olympic athletes, namely: the recent development

Configure BGP on the border routers in the private ASes so that the prefix and one sub prefix is announced to the direct peer on one link, and just the aggregate is

In order to elaborate the main problem, the research problem was “To what extent does poem as media improve the students’ ability in writing descriptive text at the tenth grade of

Corporate Treasury SMA Investment Options. FDIC-Insured

The 16 th College of Physicians Lecture, held in conjunction with the College of Physicians Dinner & Lecture on 31 October 2019, was delivered by A/Prof Christopher