ASA balancing to two routers

Hi all

Is there anyway that I can balance workloads on both routers.

I have an ASA with two attached routers each router has two instances of HSRP runs on each with its own IP address, each router is the main for one of the instances of HSRP. If there was no ASA in the way that I would set DHCP to browse through all of the functions of server through another hey presto (of sort) load balancing. However, I can't do what the ASA has only a single internal IP address. Routers treat natting because they are on different IP ranges on different Internet service providers.

I can't use GLBP as the external IP evolution would break VPN RDP and SMTP connections.

Is it possible that I can make the road ASA based on the source IP address, or any other means to separate the traffic between two routers?

Thanks in advance,

Scott

You cannot route based on ip source with only firewall with router possiable by ACB

You can give each of them point to router deffrent with metric deffrent from the static routes

in this case, it will make the topology as active standby, which is not good in your case

but you can use sub interfaces on your case make the ASA NRTIs each subinterface in deffrent subnet and deffrent security level

and let each subinterface use deffrent hsrp instance

or there is another way

IF you are not using VPN on your ASA you can reach in the context of multiple

in the context of several you're going to separate your firewall virtually

so if you have two VLAN in your network (two subnets deffrent)

then each subnet use almost deffrent firewall

goona u divide the internal interface to two subinterfaces

and you can use a shred of interface between the context outside or separate for two subinterfaces

and assign these interface for each context

If you go to each context as firewall deffrent

and you can use the HSRP deffrent on each context instance

but the multiple context, you can use VPN on the firewall

Use the following method *.

The OTHER WAY THAT ALSO I have SUGIST YOU to TRY, this IS THE Transparent firewall

in the case your firewall works in L2 mode

so you can use routers in HSRP IPS AS there is no firewall in the path

which i thnk useful for you case also

in transperant mode the way to defaultgate for your customer will be the hsrp IP because the firewall will not have everything except IPs management

the useres will also be in the same IP subnet as the gateway in your case HSRP VIP

and also, you can control the security of the network through the firewall normally

try this way and let me know

See the following link for the configuration

http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a008089f467.shtml

Please, note useful

Tags: Cisco Security

Similar Questions

  • I have two routers. My new computer will only connect to one. How can I connect at once?

    My daughter gave me a computer Acer 1 G.  I have 2 routers at home to send the wireless signal further to a computer downstairs.  Now, Acer will connect to the first router, but signal won't go in a room in the House.  I need Acer to connect two routers.

    Hello

    ·         How many computers are connected to the network?

    Method 1:

    I suggest you follow the network troubleshooting steps from the link provided below and check if it helps:

    http://Windows.Microsoft.com/en-us/Windows7/using-the-network-troubleshooter-in-Windows-7

    Method 2:

    See also the link provided below regarding:

    Solve problems, find wireless networks (link also applies to Windows 7)

    http://Windows.Microsoft.com/en-us/Windows-Vista/troubleshoot-problems-finding-wireless-networks

    Hope this helps,

  • E1000 - two routers come... 1 network leaves...

    Yes, he stole from Thunderdome, but he's not going to my question. I have 2 e1000s and bring them all to two internet are relatively simple. What is not so simple, for me, is to see these two places (each router & computers) as a major network, I can do the little file sharing. Two routers are connected via a CAT5 cable long enough. However, I will use different operating systems with them (Liunx, Windows, OS x, Android, XBox360, etc.) and I need them all see each other at both ends. I want them to leave with a nice, clean for the first router 192.168.1.1 and ask the second associated as 192.168.1.2 (using MAC address... reservations IF possible). I guess that the installer on the second router will have to be done manually and the DHCP should 'probably' be disabled so the first router can assign all IP # s. problem is, I'm not on my period on the manual configuration of the second router. I have tried setting up and had this message on the IP address of the router in router subnet 1 s 2. The last time I did any 'real' network has more than ten years and I'm rusty on all this. Basically I have not sat down and read the books involving all this because that, even if I am amazing on learning by example, I have a bit of a learning issue with books... she sucks and I am one of those who simply cannot get certain techno-jargon to stay in my brain, unless someone it simplifies a bit. Can someone point me in the right direction to sorta? PS - until I get all these answers to 'use the search engine', I already did. But a search engine can be one of two things, useful or useless depending on the person knowing the right words to use (and I obviously didn't). Again, it is a problem for me in some cases. If someone knows the answer, I'll be very grateful and I'll be more than happy to say 'thank you '. If you don't know the answer, just be an adult and leave that would be.

    1. follow the number 1.  LAN - LAN

    http://www6.nohold.NET/Cisco2/UKP.aspx?VW=1&articleid=3733

    2. in addition, I click on the Security tab of the secondary router and uncheck "filter anonymous internet requests".  You will probably have to do it, but for some reason, I have to do this on an older linksys operate between main router and router secondary file share.

    The above configuration is that I use and I have no problem sharing files between computers.

  • Connecting two routers WRT54G2 to extend the signal

    I have available two routers wireless broadband Linksys G (WRT54G2), given to me by a family member. We use one of the routers by itself for some time, but have no adequate signal throughout our House. I decided it would be easier to design the floor plan of the House for you to see his situation compared with the rest of the House on the walls that do not. We have the HughesNet satellite internet which is on the roof just about the location of the modem and router at the bottom right of the image.

    What do you think would be the best location of the main router? I read it would be more centrally located, because the signal travels horizontally and vertically. I just bought a 100' Ethernet cable being the only one that we had what the HughesNet Installer provided us with which is about 4'. I initially thought I would be the cable from main router to the basement where the second router is placed since the signal there is about 1 in 3 bars on my iPhone. The signal on the floor in the ranges of the main room (room at the top in the middle of the image) of 3-5 off 5 bars on my laptop.

    I wanted to just put a post sooner rather than later to see what your views were on the location of the main router and I have to increase the signal.

    Let me know if you have any questions to a better response.

    I have updated the firmware on the main router.

    If you want to configure the router as an access point 2 then the connection will be LAN to LAN which means the LAN port of the router port main o the 2nd router's LAN... But before you connect to the main router.

    You should first connect the 2nd router to your laptop, go to the configuration page. Configure wireless settings it is firstly, ethier you set up another name and password is all up to you. Then change the IP address to a number of 192.168.1.x(any fera l'affaire) and disable DHCP... then after that connect to the main router.

  • connecting two routers, different ISP

    I have a BEFSR41 on Charter broadband, to 20 MB, and a WRT54GL connected to AT & T DSL at 1.5 MB.  I would like the AT & T DSL to be my "rescue" if my broadband fails; but here they are on the same network, so that I can connect as and share resources.  Is it possible to do this with my current gear?  I don't want to slow down broadband connections and would love to be able to choose which network, if necessary.  (Is this bridge?)

    It is not possible. Those are mainstream devices and do not support failover router. The best you can do is to configure two routers to work independently with their internet connection. That power to one of them. If you need pass, you have to rewire and switch on the other router. I think that there is no other alternative...

  • Two routers on the same network wireless?

    Last night I bought a WRT160N, to replace my old WRT54G. The 160N is now in my room, connected to a cable modem. The 160N ethernet ports, I have a cable that goes from my room, through my attic and comes out in my living room. In my living room, I'm willing to hang the cable that comes from my 160N to my WRT54G. Then ports ethernet on my WRT54G, I want to connect my Playstation 3 and Xbox 360. I have this connected physically this way, but the PS3 does not connect to the internet through this wired connection. (Have not tried the Xbox 360)

    Basically, I'm eager to share the connection from my wall between my PS3 and the Xbox 360 so that they both have wired connections. Also, I would like to know if I can have both routers broadcast wireless on the same channel, so they appear as two wireless networks. Is this possible?

    Looks like you will get almost everything on your wish list.  You can have two wireless routers, and they can both diffuse.  Normally, you would use the same SSID for both routers, but different channels.  Your wireless computer automatically selects the channel harder, so you can "roam" between two routers.  However, this "roaming" is not as good as with cell phones, then you should only "roam" when your wireless connection is idle (i.e. not an active download).

    See my post on this topic for more information on the configuration of your system:

    http://forums.Linksys.com/Linksys/board/message?board.ID=Wireless_Routers&message.ID=108928

  • Problem setting up Port Forwarding with two routers.

    I can't set up by Linksys RT31P2 and routers port forwarding WRT160Nv3.

    My setup is Webstar Modem = RT31P2 = WRT160N = Mac OS 10.6.5. (No configurable modem and ISP do not prevent port forwarding. It comes with two Linksys routers).

    I had a Monty Python-going around with the support of Cisco cat; and follow up with telephone assistance in which the agent knew nothing about port forwarding and his supervisor expressed the view that it was not possible with two routers. Sigh.

    If anyone can help me with step by step specific and simple instructions to configure routers. I know that the basic procedures. I'm not clear, what exactly changes on routers.

    I read that portforward.com has to say and it does not work so I must be misunderstanding something.

    The ip address of my computer is 192.168.1.103.  Are the last three digits of this speech concluded the two routers in the area on the port forwarding page? What other changes should be done what router?

    I know the port numbers that I use are OK because I can implement successfully if I connect to one or other of the routers (but not both), and my software of p2p shows port are open.

    Any help and suggestions most welcome.

    If you set up as I have suggested that you have only a single LAN that will be using in your addresses * 192.168.15 case. So in your case:

    1. change the address LAN IP of 192.168.1.1 to 192.168.15.2 WRT.
    2 disable the DHCP server.
    3. connect the LAN of the WRT port to port LAN of the RT.

    That's all. Disable the DHCP server will not affect whatever it is that you're connected LAN - LAN and DHCP server on the RT is still operational.

    After the change, previously the WRT computers may require a reboot to get a new address 192.168.15. *.

    Your computer to which you are transferring must have an IP static and not dynamic (or variable). Check the current IP information on this computer. It must have an IP address like 192.168.15.103, mask 255.255.255.0, gateway 192.168.15.1 subnet and DNS 192.168.15.1 server or maybe two other IP addresses instead. Note DNS servers if you do not 192.168.15.1.

    Then configure a static IP address on the computer. Use something like 192.168.15.10, 255.255.255.0 gateway 192.168.15.1 and the DNS servers you found before.

    After this implement 192.168.15.10 port forwarding.

  • Need to "bind" the two routers

    Hi guys, I need advice here.

    I just bought a new TV and a new DVD which can access the Internet for interactive stuff. But for this, I need a key specific wireless by the manufacturer or a LAN connection. I don't want to buy the key wireless, but I want to use the LAN connections (TV 1) and 1 for the DVD. Unfortunaly, I don't want a cable everywhere in my house just to tie these new devices to the Internet.

    Since I have two wireless routers, I wondered if I could 'Wireless' bind my routers to save cable. All the 'ordinary' stuff will still be connected to my main router.

    Here is what I intend to do:
    Connect my modem to my main router (WRT610N v2).
    Wireless connect my secondary router (WRT54G v3) to my main router (WRT610N v2). [this is where I need help]
    Connect both TV and DVD by wire to my secondary router.

    I hope you can help me with this...

    Thank you guys!

    Sorry, you can not connect two routers wireless with Linksys firmware.  You must use a wire to two routers in cascade.  However, it is 3rd firmware in party that will allow, DD - WRT.  Search the Web and see if it will work for you.

  • Two routers connected, but no Internet on the router downstream

    Hi, I followed the instructions in the FAQ for routers chaining daisy with only partial success.  I have a WRT54GS V6 router configured as my gateway.  The downstream router is a BEFSR41 v4.  Both have the latest firmware.

    I have visibility on the full network of machines, but the PC connected to the router downstream has no access to the internet.  PC connected to the router upstream did.

    I tried to exchange the two routers and reconfiguration, but only once the PC connected to the router upstream has access to the internet.

    Current configuration:

    Gateway - router WRT54GS

    Router IP: 192.168.1.1

    From IP ADDR: 192.168.1.100

    DHCP server: enabled

    Downstream BEFSR41 router.

    Router IP: 192.168.1.2

    DHCP server: disabled

    Any help is appreciate

    Thank you

    On a computer that has no internet open a command prompt window and type "ipconfig/all". After the output full in your next post.

    When you connect the computer to the other router must internet?

  • With two routers wrt320n wireless bridge

    Dear reader,

    I want to bridge two routers too extend my network onbuildings on my compound. I I drew of how it should be. 'Bedrade' means 'wired', "Brug" means "bridge" and "draadloos" means "wireless" its all Dutch.

    Thankgs in advance

    Regarding accurate features 3rd party firmware that we need to ask in the forums of 3rd party firmware. I think that dd - wrt and tomato two add configuration options to configure a WRT as wireless bridge. You would operate a WRT in the normal way (i.e. you don't need 3rd party firmware on that one) and the other as the bridge that connects to the first.

  • SRI-WAAS with two routers

    Hello!

    Is it possible to have two routers (including one with RSR-WAAS and the other without) on a remote site router without ISR-WAAS to use the ISR-WAAS of the other router? (I have only finddual router with dual WAAS SRI in the CVD).

    Concerning

    Michael

    Hi Michael,

    Yes it is possible.

    However, the Redirect method depends on what type of router without ISR-WAAS is:

    another report of research international-4000:

    You can use AppNav (the two routers in the same groups of Application Controller & the SRI-WAAS as the sole member af of the AV/Waas node group).

    almost any other router:

    You can use WCCP on both routers redirecting to the SRI-WAAS.

    Best regards

    Finn

  • VLAN between two routers

    Hello. I am trying to solve a practical problem and I can't seem to deliver the VLAN. The presentation is as follows:

    You have two two routers connected to each other. Each router has a switch and each switch has four related generic PC. Each PC on this switch belongs on its own VIRTUAL local network. Thus,.

    Switch 1 Switch 2
    • PC A - VLAN 10
    • PC E - VLAN 10
    • PC B - VLAN 20
    • PC F - VLAN 20
    • PC C - VLAN 30
    • PC G - VLAN 30
    • PC D - VLAN 40
    • PC H - VLAN 40

    So A PC on the router/switch 1 1 can ping ROUTER2/switch 2 E PC and it cannot ping all the others. So on and so forth.

    So I tried to adjust the C VLAN 10 PC to check if the configuration of my work, and it does. But then I tie my router and sub interfaces, set the fa0/1 interface on my switch such as trunk and permit VLAN 10, 20, 30 and 40. Now, all PC on the router can ping each other! That should not happen. Now I don't know what the problem is. Can someone help me?

    I have attached the docx and the tracer file package.

    Sorry that I just realized you don't want connectivity between all computers.

    Which is a relief, because watching your Setup, I didn't see why they wouldn't be able to :-)

    You must use the ACLs on your subinterfaces to allow only the traffic you want.

    If you want to allow any PC from any other PC on the same site to ping but only the PC in the same vlan on the other site, then use an outbound acl on the router serial interfaces.

    If you only want to allow ping between the PC in the same vlan ACL use traffic entering on the subinterfaces.

    Jon

  • Can I have load balancing for two ISP (PPPoE and PPPoA) on Cisco 897va connections

    Hello

    I have two ISP connection and I have Cisco router 897va, I want to have the load balancing for two ISP connection second connection is PPPoE connection and second is PPPOA (ATM) connection.

    It is possible to do?

    Thank you in advance.

    You can balance by TCP (the default behavior with CEF enabled) stream.  Alias a user turns off a pipe and the next user goes off the next pipe.

    Make sure that you use the nat with route map that matchers the output interface, then you just need two routes of equal cost default (a leaver each circuit).

  • Public static IPsec tunnel between two routers cisco [VRF aware]

    Hi all

    I am trying to configure static IPsec tunnel between two routers. Router R1 has [no VRF] only global routing table.

    Router R2 has two routing tables:

    * vrf INET - used for internet connectivity

    * global routing table - used for VPN connections

    Here are the basic configs:

    R1

    crypto ISAKMP policy 1
    BA 3des
    md5 hash
    preshared authentication
    Group 2
    ISAKMP crypto key 7V7u841k2D3Q7v98d6Y4z0zF address 203.0.0.3
    invalid-spi-recovery crypto ISAKMP
    !
    Crypto ipsec transform-set esp - aes 256 esp-sha-hmac TRSET_AES-256_SHA
    transport mode
    !
    Crypto ipsec TUNNEL-IPSEC-PROTECTION profile
    game of transformation-TRSET_AES-256_SHA
    !
    interface Loopback0
    10.0.1.1 IP address 255.255.255.255
    IP ospf 1 zone 0
    !
    interface Tunnel0
    IP 192.168.255.34 255.255.255.252
    IP ospf 1 zone 0
    source of tunnel FastEthernet0/0
    tunnel destination 203.0.0.3
    ipv4 ipsec tunnel mode
    Ipsec TUNNEL-IPSEC-PROTEC protection tunnel profile
    !
    interface FastEthernet0/0
    IP 102.0.0.1 255.255.255.0

    !

    IP route 203.0.0.3 255.255.255.255 FastEthernet0/0 102.0.0.2

    #######################################################

    R2

    IP vrf INET
    RD 1:1
    !
    Keyring cryptographic test vrf INET
    address of pre-shared-key 102.0.0.1 key 7V7u841k2D3Q7v98d6Y4z0zF
    !
    crypto ISAKMP policy 1
    BA 3des
    md5 hash
    preshared authentication
    Group 2
    invalid-spi-recovery crypto ISAKMP
    crypto isakmp profile test
    door-key test
    function identity address 102.0.0.1 255.255.255.255
    !
    Crypto ipsec transform-set esp - aes 256 esp-sha-hmac TRSET_AES-256_SHA
    transport mode
    !
    Crypto ipsec TUNNEL-IPSEC-PROTECTION profile
    game of transformation-TRSET_AES-256_SHA
    Test Set isakmp-profile
    !
    interface Loopback0
    IP 10.0.2.2 255.255.255.255
    IP ospf 1 zone 0
    !
    interface Tunnel0
    IP 192.168.255.33 255.255.255.252
    IP ospf 1 zone 0
    source of tunnel FastEthernet0/0
    tunnel destination 102.0.0.1
    ipv4 ipsec tunnel mode
    tunnel vrf INET
    Ipsec TUNNEL-IPSEC-PROTEC protection tunnel profile
    !
    interface FastEthernet0/0
    IP vrf forwarding INET
    IP 203.0.0.3 255.255.255.0

    !

    IP route 102.0.0.1 255.255.255.255 FastEthernet0/0 203.0.0.2

    #######################################################

    There is a router between R1 and R2, it is used only for connectivity:

    interface FastEthernet0/0
    IP 102.0.0.2 255.255.255.0
    !
    interface FastEthernet0/1
    IP 203.0.0.2 255.255.255.0

    The problem that the tunnel is not coming, I can't pass through phase I.

    The IPsec VPN are not my strength. So if someone could show me what mistake I make, I'd appreciate it really.

    I joined ouptup #debug R2 crypto isakmp

    Source and destination Tunnel0 is belong to VRF INET, the static route need to be updated.

    IP route vrf INET 102.0.0.1 255.255.255.255 FastEthernet0/0 203.0.0.2

    crypto isakmp profile test

    VRF INET

    door-key test
    function identity address 102.0.0.1 255.255.255.255

  • Is it possible to have two routers on the cable line (T1?)?

    Question?

    is it possible to have two routers on the cable line (T1?)? First router was provided by the cable operator and runs @ standard speed(802.11?), while the router I want to add is a netgear product that will perform @ 2.4 GHz and 5 GHz. is it possible to do this without interfere or affect with speed of cable of the router?

    Thank you

    Rooster

    Question?

    is it possible to have two routers on the cable line (T1?)? First router was provided by the cable operator and runs @ standard speed(802.11?), while the router I want to add is a netgear product that will perform @ 2.4 GHz and 5 GHz. is it possible to do this without interfere or affect with speed of cable of the router?

    Thank you

    Rooster

    What is the router of society provided separate cable from your cable modem? If so then why not just use the Netgear router instead of the provided ISP router?

    If it is a combination cable modem/router device and you want to run the Netgear router as a wireless access point then only...

    Here is a FAQ that will help you in this...

    http://www.dslreports.com/FAQ/11233

    Basically would be configured with a LAN IP in the same range as the IP address you get from the existing cable modem/router Netgear, Netgear is connected directly on the LAN cable port existing via a LAN port modem/router, Netgear DHCP server is disabled and that you configure the single wireless SSID, type of encryption (that is to say.) WPA2 is the best and do not use WEP) and a strong key. Here is an example...

    http://sdrv.Ms/LrESP6

    When you configure the Netgear I recommend that you connect to it with an Ethernet cable if you screw up the wireless and the DHCP part you can find and recover.

Maybe you are looking for