Thursday, November 15, 2018

ASA Utilizing Two ISPs (PBR) - Small Issue with AnyConnect

I've got PBR setup in order to utilize both of our ISPs simultaneously. I was hoping to set up AnyConnect so that users could connect inbound on either ISP (in the event that one ISP goes down for some reason).

My issue is that my secondary outside interface is unreachable from the internet. Example:

outside_1: 1.1.1.1

outside_2: 2.2.2.2

Gateway of last resort: 1.1.1.2

All outbound traffic works fine, but traffic (initiated from the internet) attempting to come in via outside_2 is dropped as it attempts to respond via the gateway of last resort, which is the gateway for the outside_1 interface. Ideally I should be able to ping either outside interface from an external location, but I can't seem to get that to work. Is what I'm doing even feasible?



No comments:

Post a Comment