jasondvox (TechnicalUser) Feb 21, 2008
I am in a fact finding, developing and designing stage.
Build of Materials:
1 Cisco 4506 with supII plus
2 Cisco ASA 5520's with ASDM 8 (4 port gige ports each)
2 ISP's (Bonded t1's @ 3mg, ISP w/eithernet @10megs seperate wan Subnets IE 12.240.X.X and 206.170.x.x both /28)
4 servers for DMZ (New)
Best protocol that all equipment has in common is EIGRP
Task:
Build secure, redundant access to internet with Loadbalancing, fail over and high access to DMZ.
With a single ASA firewall configuring "reachable static routes" is cut and dry. The asa has a feature to ping static routes and call one dead and switch route priority.
Here are the questions:
When configuring a DMZ with 2 ISP's in defferent subnets is configuring the DMZ as easy as just adding the public address and routing information? Can I nat / publish my DMZ on both ISP's? If so how?
Then to further the issue how do I accomplish the above and setup Loadbalancing on a second asa 5520?
I do not expect any one to have the "answer" but any direction is appreciated..
Thanks
I am in a fact finding, developing and designing stage.
Build of Materials:
1 Cisco 4506 with supII plus
2 Cisco ASA 5520's with ASDM 8 (4 port gige ports each)
2 ISP's (Bonded t1's @ 3mg, ISP w/eithernet @10megs seperate wan Subnets IE 12.240.X.X and 206.170.x.x both /28)
4 servers for DMZ (New)
Best protocol that all equipment has in common is EIGRP
Task:
Build secure, redundant access to internet with Loadbalancing, fail over and high access to DMZ.
With a single ASA firewall configuring "reachable static routes" is cut and dry. The asa has a feature to ping static routes and call one dead and switch route priority.
Here are the questions:
When configuring a DMZ with 2 ISP's in defferent subnets is configuring the DMZ as easy as just adding the public address and routing information? Can I nat / publish my DMZ on both ISP's? If so how?
Then to further the issue how do I accomplish the above and setup Loadbalancing on a second asa 5520?
I do not expect any one to have the "answer" but any direction is appreciated..
Thanks