<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You need to extend the LAN at in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-multi-context-mode-stretched-dmz/m-p/2910336#M171411</link>
    <description>&lt;P&gt;You need to extend the LAN at layer 2. &amp;nbsp;You could buy a layer 2 circuit (preferably QinQ) form your service provider and let them do it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you have routers you could also built an L2TPv3 tunnel between the sites and do it yourself.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jun 2016 19:43:26 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2016-06-28T19:43:26Z</dc:date>
    <item>
      <title>Cisco ASA Multi context mode - Stretched DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-multi-context-mode-stretched-dmz/m-p/2910333#M171406</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have two Cisco 5585 Firewalls across a stretched DMZ. &amp;nbsp;I was hoping to create high availability by creating the two firewalls into Multi context mode. &amp;nbsp;It failed miserably. &amp;nbsp;Don't know if it was a configuration issue or just a bad idea but had to roll back both firewalls to stand alone again.&lt;/P&gt;
&lt;P&gt;Has anyone done this sort of project before?&lt;/P&gt;
&lt;P&gt;Is their a simple way of doing this like using two load balancers instead?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I really just want&amp;nbsp;to create high availability for the servers &amp;amp; applications on the DMZ off both firewalls. &amp;nbsp;Its a pity cisco firewalls dont just do HSRP or something like that.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could i use routers to do this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;any ideas appreciated&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kevin&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-multi-context-mode-stretched-dmz/m-p/2910333#M171406</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2019-03-12T07:56:50Z</dc:date>
    </item>
    <item>
      <title>I have done it many times,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-multi-context-mode-stretched-dmz/m-p/2910334#M171407</link>
      <description>&lt;P&gt;I have done it many times, using stretched VLANs between DC's. &amp;nbsp;Works fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I recommend having redundant layer 2 patches, to prevent the "split brain" issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And make sure you stretch the failover network between them as well.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 20:33:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-multi-context-mode-stretched-dmz/m-p/2910334#M171407</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-06-26T20:33:44Z</dc:date>
    </item>
    <item>
      <title>What I want to do is have one</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-multi-context-mode-stretched-dmz/m-p/2910335#M171409</link>
      <description>&lt;P&gt;What I want to do is have one subnet 192.168.180.x/24 running across two sites.&amp;nbsp; I already have the physical subnet in place but each side has a different gateway on the 192.168.180.x network otherwise is would have a loop&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What I then tried to do was have the Cisco 5585 firewalls in Multi context mode so they would replicate across the subnet.&amp;nbsp; It seems to work ok for a few hours but then I had sync issues.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I just want to have high availability across the subnet for the servers but maybe I don't need to change the firewalls to be in multiple context mode&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;any ideas?&lt;/P&gt;
&lt;P&gt;Maybe use load balancers instead - between the two firewalls?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 15:40:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-multi-context-mode-stretched-dmz/m-p/2910335#M171409</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2016-06-28T15:40:50Z</dc:date>
    </item>
    <item>
      <title>You need to extend the LAN at</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-multi-context-mode-stretched-dmz/m-p/2910336#M171411</link>
      <description>&lt;P&gt;You need to extend the LAN at layer 2. &amp;nbsp;You could buy a layer 2 circuit (preferably QinQ) form your service provider and let them do it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you have routers you could also built an L2TPv3 tunnel between the sites and do it yourself.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 19:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-multi-context-mode-stretched-dmz/m-p/2910336#M171411</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-06-28T19:43:26Z</dc:date>
    </item>
  </channel>
</rss>

