<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA behind ASR design question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-behind-asr-design-question/m-p/2864787#M158862</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have two ASAs in active/passive failover mode behind a pair of two ASR1001 edge router.&lt;/P&gt;
&lt;P&gt;Therefore both ASAs need a link to both routers and in case of failover the IP moves to&lt;/P&gt;
&lt;P&gt;the standby box. So to establish OSPF neighborship it needs on both&amp;nbsp;ASRs two L2 trunk links I think to both ASAs. But on the ASR it's&lt;/P&gt;
&lt;P&gt;not possible to create a interface vlan like on a Cat6500 or so.&lt;/P&gt;
&lt;P&gt;With int gi0/1.&amp;lt;vlanid&amp;gt; and int gi0/2.&amp;lt;vlanid&amp;gt; it does not work because only one interface&lt;/P&gt;
&lt;P&gt;can be assigned an IP in the same subnet. I also tried to establish a port channel from the ASR to the active and standby ASA but&lt;/P&gt;
&lt;P&gt;that also does not seem to work.&lt;/P&gt;
&lt;P&gt;Can anyone give me a hint how to do design that?&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;Chris&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 00:58:16 GMT</pubDate>
    <dc:creator>Christian Boesch</dc:creator>
    <dc:date>2019-03-26T00:58:16Z</dc:date>
    <item>
      <title>ASA behind ASR design question</title>
      <link>https://community.cisco.com/t5/network-security/asa-behind-asr-design-question/m-p/2864787#M158862</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have two ASAs in active/passive failover mode behind a pair of two ASR1001 edge router.&lt;/P&gt;
&lt;P&gt;Therefore both ASAs need a link to both routers and in case of failover the IP moves to&lt;/P&gt;
&lt;P&gt;the standby box. So to establish OSPF neighborship it needs on both&amp;nbsp;ASRs two L2 trunk links I think to both ASAs. But on the ASR it's&lt;/P&gt;
&lt;P&gt;not possible to create a interface vlan like on a Cat6500 or so.&lt;/P&gt;
&lt;P&gt;With int gi0/1.&amp;lt;vlanid&amp;gt; and int gi0/2.&amp;lt;vlanid&amp;gt; it does not work because only one interface&lt;/P&gt;
&lt;P&gt;can be assigned an IP in the same subnet. I also tried to establish a port channel from the ASR to the active and standby ASA but&lt;/P&gt;
&lt;P&gt;that also does not seem to work.&lt;/P&gt;
&lt;P&gt;Can anyone give me a hint how to do design that?&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;Chris&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:58:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-behind-asr-design-question/m-p/2864787#M158862</guid>
      <dc:creator>Christian Boesch</dc:creator>
      <dc:date>2019-03-26T00:58:16Z</dc:date>
    </item>
    <item>
      <title>You'll need a switch on which</title>
      <link>https://community.cisco.com/t5/network-security/asa-behind-asr-design-question/m-p/2864788#M158868</link>
      <description>&lt;P&gt;You'll need a switch on which you can create a VLAN so you can have all four interfaces in the same layer 2 domain.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2016 07:58:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-behind-asr-design-question/m-p/2864788#M158868</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-03-03T07:58:15Z</dc:date>
    </item>
  </channel>
</rss>

