Lucky Fox IT & Telecom Knowledge Forum

ASA Dual Internet failover setup sample

Sample

###Primary Link
interface GigabitEthernet1/2
nameif internet
security-level 100
ip address 44.44.44.1 255.255.255.0

##Backup link
interface GigabitEthernet1/4
nameif internet2
security-level 100
ip address 66.66.66.1 255.255.255.0

#NAT
nat (any,internet) source dynamic sub-10.0.0.0_8 interface
nat (any,internet2) source dynamic sub-10.0.0.0_8 interface

#Route Tracking - higher preference with Primary link (1), lower preference with backup (254)
route internet 0.0.0.0 0.0.0.0 44.44.44.254 1 track 1
route internet2 0.0.0.0 0.0.0.0 55.55.55.254 254

#SLA - Monitor Primary link to 8.8.8.8 with 3 packets - if failure it will remove primary from route table
sla monitor 123
type echo protocol ipIcmpEcho 8.8.8.8 interface internet
num-packets 3
frequency 10
sla monitor schedule 123 life forever start-time now
track 1 rtr 123 reachability