Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Multiple ISP for Failover

Status
Not open for further replies.

pbxnkey

Programmer
Aug 15, 2006
191
0
0
US
I am setting up an ASA 5505 with multiple ISP connections for Failover. My question is related to the ISP DNS Servers.
I am using the ASA to hand out DHCP to the LAN. I know I can assign dns servers either globally or through the DHCP scope but it limits me to only 2 DNS Servers.
This is what I have tried:
ciscoasa(config)# dhcpd dns 4.2.2.2
ciscoasa(config)# dhcpd dns 4.2.2.2 8.8.8.8 interface inside
dns domain-lookup outside
dns server-group DefaultDNS
name-server 4.2.2.2
name-server 8.8.8.8

If the ASA Fails over I want the LAN devices to use the ISP's specific DNS Servers? Is that possible or do I have to use the same dns server?
Thanks.
 
I didnt think the 5505 had fail over capabilites? I know you can do a multiwan licence, but its techincally doesnt fail over?

ACSS - SME
General Geek



1832163.png
 
If you use ipsla to monitor the primary WAN gateway and have a weighted static route to the secondary WAN gateway it will fail over.
 
If I understand you correctly you will have 2 ISP links connected to the same ASA and will have tracked route path failover? If so, you will not be able to use ISP-specific DNS server IP addresses in your DHCP handoff because there's no mechanism to switch them when your path changes. The primary ISP would deny DNS requests coming from a "foreign" subnet, and visa versa.
Another way to handle this wold be to configure a small DNS server inside your LAN and give its IP address to DHCP clients, which would make you independent of ISP DNS services.
 
Unfortunately a DNS Server won't be possible. It's a small site. The only alternative that I see is to use google dns.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top