Hi all,
I have a quick question with regard to one of our DMZ's, which is a 2 tier model, in active/standby mode, with dual ISP's: see attached image.
We're using an SLA monitor to track a default route to ISP1, in the event of a failure a route is added for ISP2.
On the outside primary/active ASA we have a route of:
S* 0.0.0.0 0.0.0.0 [1/0] via x.x.y.1, ISP1
However, on the outside secondary/standby Asa we have a route of:
S* 0.0.0.0 0.0.0.0 [1/0] via x.x.y.1, State-LNK
I don't understand why it's trying to route to ISP1 over the Stateful failover interface rather than using it's trunked outside interface. When the secondary becomes active the whole DMZ grinds to a halt as the route remains over State-LNK!
We have a copy of this setup at another site, which works fine. I've taken all the configs and used a comparison tool, and can't see any significant differences.
My initial thoughts we're a trunking/vlan problem, but all vlans are correct and all required interfaces are trunking.
Any ideas why it's doing this? Anyone seen this before?
Thanks in advance - I truely am lost!
Colin
I have a quick question with regard to one of our DMZ's, which is a 2 tier model, in active/standby mode, with dual ISP's: see attached image.
We're using an SLA monitor to track a default route to ISP1, in the event of a failure a route is added for ISP2.
On the outside primary/active ASA we have a route of:
S* 0.0.0.0 0.0.0.0 [1/0] via x.x.y.1, ISP1
However, on the outside secondary/standby Asa we have a route of:
S* 0.0.0.0 0.0.0.0 [1/0] via x.x.y.1, State-LNK
I don't understand why it's trying to route to ISP1 over the Stateful failover interface rather than using it's trunked outside interface. When the secondary becomes active the whole DMZ grinds to a halt as the route remains over State-LNK!
We have a copy of this setup at another site, which works fine. I've taken all the configs and used a comparison tool, and can't see any significant differences.
My initial thoughts we're a trunking/vlan problem, but all vlans are correct and all required interfaces are trunking.
Any ideas why it's doing this? Anyone seen this before?
Thanks in advance - I truely am lost!
Colin