本文转自:http://bbs.csc-china.com.cn/forum.php?mod=viewthread&tid=990787&extra=page%3D10 需求:1.Inside访问国外路由优先走HK路由器(假定61.128.0.0/8为国内路由,其他都为国外路由)2.Inside访问国内路由优先走ADSL路由器3.DXoutside接口对外提供L2L和anyconnect VPN,允许访问Inside 备注:测试用的ASAv9.91,如果用ASAv9.71相同的路由配置,SSL VPN和L2L VPN会无法连通。二.基本配置1.ASAv防火墙hostname ASAvinterface GigabitEthernet0/0 nameif HKoutside security-level 0 ip address 202.100.1.10 255.255.255.0 no shutdowninterface GigabitEthernet0/1 nameif DXoutside security-level 0 ip address 202.100.2.10 255.255.255.0 no shutdowninterface GigabitEthernet0/2 nameif ADSLoutside security-level 0 ip address 202.100.3.10 255.255.255.0 no shutdowninterface GigabitEthernet0/3 nameif Inside security-level 100 ......Read More>