<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local ASA active/active and multiple DC active/active in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088774#M394177</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi&lt;BR /&gt;&lt;BR /&gt;Firstly, thanks for taking an interest&lt;BR /&gt;&lt;BR /&gt;In answer to your questions&lt;BR /&gt;&lt;BR /&gt;1. The active/active ASAs in each DC are for traffic to an from the Internet&lt;BR /&gt;2. The DCs are connected without FWs as the links are non-public&lt;BR /&gt;3. The full/partial is relatively straightforward - within a DC if an ASA fails, not an issue the other takes over. If both ASAs fail, traffic needs to be routed to the other DC and ideally this needs to maintain previously initiated traffic flows hence the requirement to have active/active between the DCs.&lt;BR /&gt;&lt;BR /&gt;Does this help?&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Dec 2012 08:46:05 GMT</pubDate>
    <dc:creator>Ian Terry</dc:creator>
    <dc:date>2012-12-13T08:46:05Z</dc:date>
    <item>
      <title>Local ASA active/active and multiple DC active/active</title>
      <link>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088772#M394175</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi&lt;BR /&gt;&lt;BR /&gt;Trying to work through a tricky issue - customer has 2x DCs in geographically diverse locations. Each DC is resilient in terms of networking on all fronts. If a data centre fails, traffic is routed through the other DC - nothing unusual. We have multi-Gigabit links between DCs. Core backbone is N7k&lt;BR /&gt;&lt;BR /&gt;In terms of security each DC is provided with a pair of active/active ASAs.&lt;BR /&gt;&lt;BR /&gt;Ideally we need to get an active/active between DCs so that in the event of a full (or partial) DC failure, the other DC will be aware of the sessions traversing across the "failing" DC. Response time between DCs is well within guidelines, this is not the issue.&lt;BR /&gt;&lt;BR /&gt;Any thoughts on how this could be achieved?&lt;BR /&gt;&lt;BR /&gt;Many thanks in advance.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:36:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088772#M394175</guid>
      <dc:creator>Ian Terry</dc:creator>
      <dc:date>2019-03-12T00:36:36Z</dc:date>
    </item>
    <item>
      <title>Local ASA active/active and multiple DC active/active</title>
      <link>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088773#M394176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;before I can offer my opinion, can you elaborate on the followings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Active/Active for ASA at each data for internet facing applications?&lt;/P&gt;&lt;P&gt;- Any firewalls between the multi-Gigabit links between the DCs?&lt;/P&gt;&lt;P&gt;- can you provide a specific example for "full" or "partial" DC failure?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 02:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088773#M394176</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2012-12-13T02:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Local ASA active/active and multiple DC active/active</title>
      <link>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088774#M394177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi&lt;BR /&gt;&lt;BR /&gt;Firstly, thanks for taking an interest&lt;BR /&gt;&lt;BR /&gt;In answer to your questions&lt;BR /&gt;&lt;BR /&gt;1. The active/active ASAs in each DC are for traffic to an from the Internet&lt;BR /&gt;2. The DCs are connected without FWs as the links are non-public&lt;BR /&gt;3. The full/partial is relatively straightforward - within a DC if an ASA fails, not an issue the other takes over. If both ASAs fail, traffic needs to be routed to the other DC and ideally this needs to maintain previously initiated traffic flows hence the requirement to have active/active between the DCs.&lt;BR /&gt;&lt;BR /&gt;Does this help?&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 08:46:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088774#M394177</guid>
      <dc:creator>Ian Terry</dc:creator>
      <dc:date>2012-12-13T08:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Local ASA active/active and multiple DC active/active</title>
      <link>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088775#M394178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1- For inbound traffic from the Internet, that will be possible if you use F5 GTM (I am a Cisco person when it comes to routers and switches but anti-cisco when it comes to Firewall, load balancers &lt;SPAN __jive_emoticon_name="mischief" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt; and other things, I just things there are better vendors out there than cisco); however, you will NOT be able to maintain previously traffic flows.&amp;nbsp; New traffics will be re-directed to the new DC by the GTM but existing traffic flows will not be maintained.&amp;nbsp; If you think about it, that makes perfect sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- for outbound traffcs, assuming that you have your routing design properly, this will work as well.&amp;nbsp; If both ASAs in DC1 fail, the server will know how to use multi-gigabit link between the DC and go out of ASA on DC2; however, since the ASA is "stateful" firewall, any previously initiated traffics will be lost, only new connections will work;&amp;nbsp; if you want to maintain previously traffic flows, it will be possible with routers (without firewall) because routers can handle asymetric routing (or maybe ASA can handle as well with tcp-bypass feature)&amp;nbsp; but I don't think it will work either because in this design, the destination servers is expecting you're coming from the same IP address (NAT'ed I assume) in both DCs.&amp;nbsp; when DC1 is down and you're using DC2, you will be using a different NAT'ed, thus breaking previous traffics flow.&amp;nbsp; Is it possible, yes?&amp;nbsp; Difficult to achieve, hell yes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 10:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088775#M394178</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2012-12-13T10:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Local ASA active/active and multiple DC active/active</title>
      <link>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088776#M394179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for this - Cisco throughout I'm afraid.&lt;BR /&gt;&lt;BR /&gt;Yes it is difficult and appreciate the support.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 12:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-asa-active-active-and-multiple-dc-active-active/m-p/2088776#M394179</guid>
      <dc:creator>Ian Terry</dc:creator>
      <dc:date>2012-12-13T12:05:21Z</dc:date>
    </item>
  </channel>
</rss>

