BGP/Multi Homing

bgpcisco-asa

We currently have an ASA5505 and are getting a 2nd ISP (both ISPs will have 20 up/down dedicated fiber).

We need to be able to setup BGP/Multi-homing but I have found that the ASA's do not support this. This is due to the fact that they are more firewalls (with the NAT ability) then a router.

What sort of hardware are we going to require for this functionality? We will require two of them to be able to be configured as a failover pair.

Currently, both of our ASA's have Security+ and are set as a failover array.

Best Answer

You have a few choices. One possibility is just to put two cheap PCs in front of the ASA5505s. One PC would act as your 'border router' to each ISP and run BGP both with the other 'border router' and with that ISP. You would then have your own ISP network coming out of the border routers, which you could connect your firewalls to.

You can use whatever OS or platform for the PCs you are comfortable with. OpenBSD, FreeBSD, Linux, or router-specific distributions all exceptionally work well at 100Mbps or less.