<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-integration/m-p/2903940#M153991</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It depends mostly on the amount of traffic you must be passing through the ASA's.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What is the load, what type of traffic is it ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can configure ASA clustering on the external FW's that would help you to load-balance the traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ha_cluster.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
    <pubDate>Wed, 11 May 2016 13:14:28 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2016-05-11T13:14:28Z</dc:date>
    <item>
      <title>Firewall Integration</title>
      <link>https://community.cisco.com/t5/network-security/firewall-integration/m-p/2903939#M153990</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I need some design assistance for data center firewall build, as customer has 4 firewalls as per below; for which i need to combine below in 2 ASA 5585-SSP-20 (1 pair for External, 1 pair for Internal) , so what are the things i need to consider for designing?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;3 External facing FW's( Internet+Anyconnect+Site to Site VPN FW, Offload internet for remote sites FW, EDI FW)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;1 Internal (PCI involved)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Thanks and Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Sankar&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 01:09:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-integration/m-p/2903939#M153990</guid>
      <dc:creator>skrsubramaniyam_CTS</dc:creator>
      <dc:date>2019-03-13T01:09:39Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/firewall-integration/m-p/2903940#M153991</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It depends mostly on the amount of traffic you must be passing through the ASA's.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What is the load, what type of traffic is it ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can configure ASA clustering on the external FW's that would help you to load-balance the traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ha_cluster.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 13:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-integration/m-p/2903940#M153991</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-05-11T13:14:28Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya,</title>
      <link>https://community.cisco.com/t5/network-security/firewall-integration/m-p/2903941#M153992</link>
      <description>&lt;P&gt;Hi Aditya,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;That was not answered my question, my intention not only for load-balancing, also i need to design the network based on compliance as well. as said above, in my new requirement i have 1 pair ASA available for external (Perimeter) &amp;nbsp;traffic like&amp;nbsp;&lt;SPAN&gt; Internet+Anyconnect+Site to Site VPN FW, Offload internet for remote sites, another 1 pair is available to accomodate internal traffic like PCI, EDI segments. Mainly most of the remote offices are connected thru DMVPN tunnel as secondary path for corporate internet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Remote locations Types:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type1 = Internet+MPLS&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type2 = Internet only&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Type3 = MPLS only&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In the above scenario, all corporate traffic should come thru MPLS and internet should come thru DMVPN, only in Type1 if MPLS is down corporate&amp;amp; internet traffic comes thru DMVPN tunnel. in this topology which is best way to place firewall to pass through the traffic?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 18:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-integration/m-p/2903941#M153992</guid>
      <dc:creator>skrsubramaniyam_CTS</dc:creator>
      <dc:date>2016-05-13T18:24:11Z</dc:date>
    </item>
  </channel>
</rss>

