Cisco Firewall :: Load Balancing Using Virtual IP On DMZ Interface Of 5520 ASA

Feb 21, 2012

We want to achieve a load balancing scenario using Virtual IP on DMZ interface on a Cisco ASA 5520.
The IPs we are going to use on DMZ are and
These IPs are going to be NATted to all inside IPs.
Lets say our outside IP is X.X.X.X
This IP points to and with .2 being the primary and .3 being the secondary. When I hit the outside IP, it should point me to .2 and that .2 should take me to the inside IPs.

View 1 Replies


Cisco Firewall :: 5520 Internet Link Load Balancing

Sep 26, 2011

We use Cisco ASA 5520 (in HA configuration) connected to Cisco Switch 3750, ISP connection (25 Mbps) is straight to cisco 3750 switch. Since, Internet traffic is now high, a seecond ISP will be added.Our plan is to do Internet Link Load Balancing. My understanding that AS5520 can not do balancing.What appliance do you think I can use to accomplish the link balance?Also, take in consideration that our current ASA is also our VPN server and there are two DMZ zones.

View 1 Replies View Related

Cisco VPN :: Load Balancing ASA 5520

Sep 13, 2011

We have an ASA5520 pair that we will be installing to load balance SSLVPN connections.  Below is a portion of our configs pertaining to the VPN load-balancing feature (configured on both ASAs):My specific question is related to routing of return traffic to load-balanced VPN sessions.  Is there some kind of persistence function that tells the return traffic which ASA to route back to?  For instance, if ASA1 has a VPN connection having IP address associated to it, and ASA2 has a VPN connection having IP address, how does the return traffic for each connection know which ASA to route back to?

View 1 Replies View Related

Cisco VPN :: ASA 5520 - Load Balancing And Failover

Jul 25, 2011

We have two asa5520 configured as primary and standby unit in fail over configuration, and all is working properly. Is it possible, with this configuration (fail over), to configure vpn load balancing/clustering?

View 7 Replies View Related

SRX210 / Load Balancing Router With HA And T1 Interface?

May 20, 2011

I'm setting up a warehouse near Dayton, OH which will require a high level of network availability as there will be no local IT staff. To that end I've decided that a router that supports load balancing of 2 WAN connections, HA, and a T1 interface would be ideal. To clarify the load balancing requirement, the location will have redundant internet access plus a point to point T1 to the main office to facilitate low latency connectivity between a warehouse management system and ERP back-end. Total user count at the warehouse is 5 and 20 at the main office. Neither location has tremendous bandwidth requirements.

I have little practical experience in this area, but I have come up with 2 solutions thus far.

(2) Juniper SRX210
Vyatta Core 6.2 w/ Sangoma T1 interface adapters

The Juniper solution is likely a safer route given access to vendor support, however, this option becomes rather spendy as I'd like to use the same configuration at the main office which will require 4 units. The Vyatta option, although probably less proven and a bit more risky, could run on a pair of Sun x4100 systems at each location which I can purchase for around $200 each plus the cost of the Sangoma cards.

View 1 Replies View Related

Cisco VPN :: ASA 5520 - Load Balancing With Active / Standby Failover

Jul 8, 2010

1) 2 x ASA 5520, running 8.2
2) Both ASA are in same outside and inside interface broadcast domains – common Ethernet on interfaces
3) Both ASA are running single context but are active/standby failovers of each other. There are no more ASA’s in the equation. Just these 2. NOTE: this is not a Active/Active failover configuration. This is simply a 1-context active/standby configuration.
4) I want to share VPN load among two devices and retain active/standby failover functionality. Can I use VPN load balancing feature?
Active/Active failover is understood to mean only two ASA running multi-contexts. Context 1 is active on ASA1 Context 2 is active on ASA2. They are sharing failover information. Active/Active does not mean two independently configured ASA devices, which do not share failover communication, but do VPN load balancing. It is clear that this latter scenario will work and that both ASA are active, but they are not in the Active/Active configuration definition. Some people are calling VPN load balancing on two unique ASA’s “active/active”, but it is not
The other confusing thing I have seen is that VPN config guide for VPN load balancing mentions configuring separate IP address pools on the VPN devices, so that clients on ASA1 do not have IP address overlap with clients on ASA2. When you configure ip address pool on active ASA1, this gets replicated to standby ASA2. In other words, you cannot have two unique IP address pools on a ASA Active/Standby cluster. I guess I could draw addresses from external DHCP server, and then do some kind of routing. Perhaps this will work?

View 5 Replies View Related

Cisco Switching/Routing :: Asa 5520 Load Balancing Based Upon Http Or Https

Mar 5, 2012

I have a customer who wants his new ASA-5520 to load balance out-going traffic between 2 ISPs, fairly normal request. Now here's the twist. He wants to separate traffic based upon the protocol used, http to one ISP, https to the other.

View 3 Replies View Related

Cisco Firewall :: ASA 5545X And Two ISP Load Balancing

Mar 2, 2013

I have two Internet connections which are connected to two ISR 2951s. Also I have two ASAs 5545-Xs, which I want to use in Active/Active failover mode with multicontext. The question is: how can I configure ASAs to perform ISP load-balancing as well?

View 4 Replies View Related

Cisco Firewall :: ASA 5540 Load-balancing Over EIGRP Not Working

Nov 15, 2011

We have an ASA 5540 running 8.4(1) on the inside of dual Internet-facing border routers. The routers run BGP facing out and EIGRP facing in, with the ASA also running EIGRP for the same AS. Both routers redistribute a default route into EIGRP. It was my understanding and expectation that the ASA would learn both of these, as they are equal cost, and load-balance the outbound traffic over the two links. This does not appear to be the case.
The routers both have:
router eigrp 100
network nn.nn.nn.nn
redistribute static


View 9 Replies View Related

Cisco Firewall :: Configuring Virtual MAC Addresses On ASA 5520?

Jul 21, 2012

I configure the virtual MAC address for a interface on ASA 5520, will enter the following command on the active unit:
failover mac address Inside 0012.3456.789a 0023.4567.89ab
The active MAC address is of the same as the Inside's burned-in MAC address of the active unit.Similarly, the standby MAC address is of the same as the Inside's burned-in MAC address of the standby unit.Do I get the effect of failover mac address command?

View 1 Replies View Related

Cisco Firewall :: 5580 Not Pinging Virtual Interface

May 1, 2012

I have got new cisco ASA 5580 running 7.2(4) on it  when i am trying to configured Virtual interface on vlan 400 in  Gi0/0.400 to the problem is from my MZ zone to Lbase virtual interface iam not able to ping.

View 2 Replies View Related

Cisco Firewall :: 4710 - Unable To Ping From MZ To Virtual Interface Of ASA

May 3, 2012

one of my SNMP server sits in MZ zone,and ACE 4710 is connected to core switch,coreswitch is connected to firewall asa.
Now iam trying to ping from MZ zone SNMP server to loadbalancer ip,iam unable to ping my LB interface to discover SLB on my SNMP server.

View 1 Replies View Related

Cisco Firewall :: ASA 5520 Refuses To Load 8.x Code?

Oct 17, 2011

I have a ASA# here that refuses to load 8.x# code. I do not have an issue loading 7.x# code at all. When I power on the ASA# it does not pass the fsck#.
Loading /asa842-k8.bin#... Booting...Platform ASA5520# Loading...IO memory blocks requested from bigphys# 32bit#: 20848dosfsck# 2.11, 12 Mar 2005, FAT32#, LFN#
I have tried 8.0, 8.2, 8.3, 8.4 codes. I have also swapped RAM and flash.

View 5 Replies View Related

Cisco Firewall :: ASA 5520 Webpages Will Not Load Correctly

May 3, 2012

I recently implemented an ASA 5520 HA pair with CSC-SSM-20s in each non stateful per cisco.  The CSC management sits in a management subnet with the management interface of the ASA as its default gateway in the same subnet.  Ever since the implementation frequently webpages will not load correctly, the formating will not look right and pictures will be red x.  If you hit f5 to refresh the pages loads fine.  If I add a deny any any eq 80 rule before the permit any any eq 80  the issue appears to go away.  TAC can't seem to find anything worng.  All we want to do is use a simple web content filter with the check boxes in the global filtering policy.  ASA is running 8.2(5) and CSC is running 6.3.1172.0.  Everything else works fine SVC and rules and such.  [code]

View 2 Replies View Related

Cisco Firewall :: ASA 5520 - Routed Management Interface On Transparent Firewall?

May 5, 2013

I have an asa 5520.  How would I configure my dedicated management interface to be able to route off subnet while the firewall is in transparent mode?

View 1 Replies View Related

Cisco WAN :: ASR1001 / L2 Over L3 With Load-balancing?

Nov 30, 2011

i'm trying to accomplish the following:I want to trasport a bunch of vlan layer 2 etherchannel on a pair of layer3 connections, using L3 to load balance.i was considering a pair of options:
1) bridging + gre (non applicable since i cant bridge 2 interface beloging to a etherchannel to a tunnel)
2) L2TP is it possible to accomplish this with the above tecnology? any reference, configuration example?
3) AoMLPS is it possible to accomplish this with the above tecnology ? any reference, configuration example?
I cant modify topology, the routers used are ASR1001 It is mandatory that both sites have a layer2 connection between them.

View 1 Replies View Related

Cisco WAN :: 2811 DSL Load Balancing

Dec 9, 2010

I have a Cisco 2811 router with two HWIC-ADSL cards configured for dsl connection. I have two lines from the same ISP and i am load balancing between them. I have created a couple of SLA's to check the state of the connections and add to the routing table the two default routes if both are up or any one of them is up.My problem is that when i  try to download big files (especially antivirus updates) the download at some point stops (especially the antivirus exits with an error of unreachability). If i shut down one line everything works fine.Could i use something (configuration-wise) to prevent this problem from happening?????Is there any way i can combine the two lines? They are simple ADSL connctions with static ip's.

View 8 Replies View Related

Cisco WAN :: Load Balancing On ASR1002?

Jun 25, 2012

One of our customer just purchased ASR1002 router, they have three internet links from different ISPs and they dont have any remote site, they have three different public IP pool as their respective ISPs. So, is it possible to load balance the internet traffic using all three link on Cisco ASR router ( IOS - Advance Enterprise Services)

View 3 Replies View Related

Cisco WAN :: 4506-E DSL Load Balancing

Jun 10, 2012

I need to configure DSL Load Balancing on Core Cisco Switch 4506-E. I have a Router Cisco 2811 with 2GE Ports and a Firewall Cisco ASA5505. I have 8 Physical DSL Connections with 1Mb each. I need to combine that 8 Mb on Core Switch and allow each end user to access the Internet via the available DSL connection which means that every user has 8 Mb available.

View 7 Replies View Related

Cisco VPN :: Load Balancing ASA 5510

Sep 13, 2011

Currently we have deployed site to site vpn between 2 asa 5510 model. one is corporate site and one is remote site. now we plan to use radware load balancer in which 2 isp will terminate. now if at a remote site wecreate only 1 ipsec tunnel and mention sigle isp peering. if one isp fails at corporate how remote site will be access by site to site vpn through 2 isp vpn. what thing we need to do over asa as well as load balancer at both end.

View 6 Replies View Related

Cisco Application :: URL Load Balancing In ACE 20?

May 23, 2011

I have 2 rservers,,I have 3 URLs in both

I want to have only one link for two same link in both servers with this ip address so I will have 3 link and will load balance to 6 links


View 4 Replies View Related

Cisco WAN :: WAN Load Balancing On 2811

Apr 18, 2012

i have a one 2811 router with 2 nos of HWIC-1FE card, and also i have two mpls connection [code] how can i configure it with mpls load balancing ?

View 10 Replies View Related

Cisco :: Check Load Balancing On The Routers Using BGP?

Apr 8, 2011

How is the best and easiest way to check kind of load balancing on the routers using BGP (Border Gateway Protocol)?

View 6 Replies View Related

Cisco WAN :: 11501 CSS Load / Advance Balancing

Mar 1, 2011

We have Cisco CSS 11501 and connected in  One-Arm way.Currently there are 4 source sending traffic and 3 server to  receive the request. We are using Advance-balancing with Source IP. So  the ratio become 2:1:1 or 1:2:1 or 1:1:2.But our target is to do the load balancing in equal ratio.

View 1 Replies View Related

Cisco Routers :: RV016 Is Not Load Balancing UDP?

Feb 22, 2012

this router (RV016v3, Firmware: v4.1.1.01-sp (Dec 6 2011 20:03:18)) in regards to it not properly directing UDP packets out of the right WAN, as per the settings stored in Protocol Binding section of [System Management, Multi-WAN].I use the section to direct all traffic from desktop computers ( ~ through WAN4, and all VoIP related traffic ( ~ through WAN2(PPPoE).Everything seems to be working well except for some of the UDP traffic from which is seen in the log going out of WAN4 instead of WAN2.I have even created a new entry for [UDP/5060~5060]->, and placed it at the very top of the list.Here are a few lines that I've observed in the log: (Refreshed the registration of two SIP Trunks configured in our PBX)
Feb 23 18:11:47 2012     Connection Accepted     UDP> on eth4
Feb 23 18:11:46 2012     Connection Accepted     UDP> on ppp2
Feb 23 18:11:46 2012     Connection Accepted     UDP> on eth4
Feb 23 18:11:46 2012     Connection Accepted     UDP> on ppp2
There are no static routes configured, so i'm baffled by what could cause some of the UDP packets to go through the wrong WAN.All TCP Traffic from is seen going though WAN2 as it should.

View 2 Replies View Related

Cisco WAN :: ASR1001 - Internet Load Balancing

Feb 3, 2013

I want to load balance my Internet traffic between two ASR 1001 routers that are connected to our core switches.  Both routers are connected to the same ISP (Comcast) going to the same BGP AS on different /30 subnets.  Is there a way for me to load balance my Internet traffic using both connections with BGP rather than having one of these connections sitting idle?  If not, the only solution I see is to configure my layer 3 devices to split internet traffic between both routers (i.e. default routes with same AD).

View 6 Replies View Related

Cisco WAN :: 2821 / 881 - Load Balancing Between Two Routers?

Feb 24, 2011

We have a network topology like 2821 router with MPLS link and 881 Router with DSL Connection(DMVPN).

MPLS Link runs in BGP
DSL Connection runs in EIGRP.

So the existing scenario is like When ever MPLS link goes down Traffic will be moved to DSL connection. and once it come again it will be moved back to DSL using HSRP we are doing this. in this case most of the times my DSL connection will be in standby mode.Now my management decided to use both the links in active state and want to do some load balance between the links for some specific traffic like Internet, WSUS Updates, Antivirus updates need to go through the DSL connection even the MPLS is up and running.

View 2 Replies View Related

Cisco Routers :: RV042 Load Balancing And OWA

Apr 6, 2012

I have a rv042 router with two internet connections. I have setp the WAN1 and WAN2 and set the load balance mode. Surfing on internet is then not a problem and I checked that I was using the two internet connection.However if I try to connect to my corporate (OWA) outlook web access i am looping on the first page where I should provide my credentials.I know that most of the load balancer could be set up with a sticky bit to keep the session on the same WAN connection.

View 4 Replies View Related

Cisco Application :: 389 Load Balancing LDAP In ACE?

Dec 5, 2011

Does loadbalancing ldap services in ACE? Both port 389 and 636.

View 4 Replies View Related

Cisco WAN :: CEF - Per Packet Load Balancing (3560)?

Jul 5, 2011

confirm is Per packet load balancing is supported in the 3560's ?
I am going around in circles, and can't find a definate Y or N answer.
I have a suspicion this CEF feature is only available on routers.

View 8 Replies View Related

Cisco WAN :: ASR 1000 Multiple ISP Load Balancing?

Nov 21, 2012

I came up with a few ideas to Load Balance based on multiple ISPs. In our network setup we have a distribution layer of 3750s going to an ASR 1000 Series Router, which goes out to multiple ISPs, ISP1 and ISP2.
we also have a virtual fortinet appliance behind the 3750. If I say all traffic going to 0 - 126 goto ISP1, and 128 - 254 goto ISP2,and then obviously whatever NATd IP the customer has (ISP1 or ISP2), the return traffic will have to go to that specific IP. The traffic will allgo back to the virtual fortinet on the same interface, so I would assume I would be safe with uPF.I don't know of any ways to load balance based on Link Optimization, without implementing a load balancer?

View 5 Replies View Related

Cisco WAN :: Load Balancing In Router 1941?

Nov 28, 2012

i have cisco 1941 router with HWIC-4EWS Card We have two ISP,  how to configure the load balancing

View 3 Replies View Related

Cisco Application :: SIP Load Balancing With ACE 4710?

Nov 8, 2011

SIP Load balancing Issue with ACE 4710?I have a Cisco ace 4710 with vesion Version A4(2.2). i configued simple SIP load balancing first without stickiness. without stikeiness we are having a problem because bye packet at the was not going to the same server all the time that left our port in used even though user hang up the phone. its happen randmly. i have a total 20 licenced ports and its fill out very quickly. so i dicided to use the stickiness with call-ID but still same issue. below is the config
rserver host CIN-VOX-31
  ip address
rserver host CIN-VOX-32
  ip address


View 6 Replies View Related

Copyrights 2005-15, All rights reserved