Forum Discussion

Jim_Sellers_473's avatar
Jim_Sellers_473
Icon for Nimbostratus rankNimbostratus
Nov 08, 2011

Link Controller and Cisco ASA VPN questions

I have a link controller with multiple ISP's it is handling routing for along with some Cisco ASA's that need to establish VPN connections to other Cisco ASA's on the internet. Does anyone have an elegant way of accomplishing failover if the link with the priority goes down? Any help would be greatly appreciated.

 

 

 

 

 

 

 

 

 

 

 

 

  • I'd create an outbound pool that contained both links and use priority group activation so link 2 is only used if link 1 is down. Since you'll need to SNAT traffic outbound to match the inbound, you'll want to do a SNAT Pool with the necessary addresses and an iRule that basically says "if this pool member is used, snat to this address."

     

     

    Let me know where you'd like me to elaborate.