<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Single firewall with 2 core switches in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853520#M489380</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is ASA5520 on Failover mode as well?&lt;/P&gt;&lt;P&gt;Or you have two separate interfaces are connected to Active-Switch and Standby-Switch on different security level ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jan 2012 20:43:37 GMT</pubDate>
    <dc:creator>rizwanr74</dc:creator>
    <dc:date>2012-01-05T20:43:37Z</dc:date>
    <item>
      <title>Single firewall with 2 core switches</title>
      <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853519#M489379</link>
      <description>&lt;P&gt;&lt;STRONG style="font-size: 12pt; "&gt;&lt;TT&gt;&lt;SPAN style="color: #3a3935;"&gt;Hi All&lt;/SPAN&gt;&lt;/TT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt; "&gt; &lt;TT&gt;&lt;SPAN style="color: #3a3935;"&gt;Following is my requirement. Two different WAN links get connected to&lt;/SPAN&gt;&lt;/TT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt; "&gt; &lt;TT&gt;&lt;SPAN style="color: #3a3935;"&gt;the firewall via two routers.(Different ip subnets).I need to get this&lt;/SPAN&gt;&lt;/TT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt; "&gt; &lt;TT&gt;&lt;SPAN style="color: #3a3935;"&gt;two wan streams seperatly to the core switches.Core switches sits&lt;/SPAN&gt;&lt;/TT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt; "&gt; &lt;TT&gt;&lt;SPAN style="color: #3a3935;"&gt;Active/Stanby senario.If the Active&amp;nbsp; core goes down Stndby Core will&lt;/SPAN&gt;&lt;/TT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt; "&gt; &lt;TT&gt;&lt;SPAN style="color: #3a3935;"&gt;have take over the traffic. Pls advice my design is correct ,if not&lt;/SPAN&gt;&lt;/TT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt; "&gt; &lt;TT&gt;&lt;SPAN style="color: #3a3935;"&gt;sugest what do i need to change. ASA is 5520.Pls help me to find&lt;/SPAN&gt;&lt;/TT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt; "&gt; &lt;TT&gt;&lt;SPAN style="color: #3a3935;"&gt;suitable sample configuration for this senario&lt;/SPAN&gt;&lt;/TT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt; "&gt; &lt;TT&gt;&lt;SPAN style="color: #3a3935;"&gt;Thanks&lt;/SPAN&gt;&lt;/TT&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853519#M489379</guid>
      <dc:creator>Kantha Wijesekara</dc:creator>
      <dc:date>2019-03-11T22:10:20Z</dc:date>
    </item>
    <item>
      <title>Single firewall with 2 core switches</title>
      <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853520#M489380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is ASA5520 on Failover mode as well?&lt;/P&gt;&lt;P&gt;Or you have two separate interfaces are connected to Active-Switch and Standby-Switch on different security level ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 20:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853520#M489380</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-01-05T20:43:37Z</dc:date>
    </item>
    <item>
      <title>Single firewall with 2 core switches</title>
      <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853521#M489381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp; &lt;A _jive_internal="true" class="active_link" href="https://community.cisco.com/people/rizwanr74" id="jive-3544109774310404165244"&gt;rizwanr74,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks for the urgent reply, The ASA&amp;nbsp; not in failover mode. Yes ,ASA should have two seperate interfaces are connected to both core switches.(Sorry its not seen on the diagram) &lt;/P&gt;&lt;P&gt;Kawi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 03:29:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853521#M489381</guid>
      <dc:creator>Kantha Wijesekara</dc:creator>
      <dc:date>2012-01-06T03:29:51Z</dc:date>
    </item>
    <item>
      <title>Single firewall with 2 core switches</title>
      <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853522#M489382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Pls help................&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 05:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853522#M489382</guid>
      <dc:creator>Kantha Wijesekara</dc:creator>
      <dc:date>2012-01-09T05:10:40Z</dc:date>
    </item>
    <item>
      <title>Single firewall with 2 core switches</title>
      <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853523#M489383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kantha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the WAN side I do not see any issues as you will send all internet traffic over one router and then the connections to the other Sites via another router. PBR is not supported on the ASA but you will be able to accomplish this particular scenario&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now on the LAN side , the ASA 5520 needs to have each interface attached to a differnet subnet, in this case you will have two interface going to 2 different switches on the same subnet witch you cannot do it. I think what you could do is to have redundant interfaces.&lt;/P&gt;&lt;P&gt;Here is one example:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ref_examples.html#wp1009432" style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; outline-style: none; color: #2f6681; font-family: Arial, verdana, sans-serif;"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ref_examples.html#wp1009432&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 05:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853523#M489383</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-09T05:51:58Z</dc:date>
    </item>
    <item>
      <title>Single firewall with 2 core switches</title>
      <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853524#M489384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio.&lt;/P&gt;&lt;P&gt;Kindly explain the LAN side which not clear to me.How I segment the Lan for different subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;KAWI&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 07:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853524#M489384</guid>
      <dc:creator>Kantha Wijesekara</dc:creator>
      <dc:date>2012-01-09T07:54:06Z</dc:date>
    </item>
    <item>
      <title>Single firewall with 2 core switches</title>
      <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853525#M489385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kantha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot use 2 interfaces at the same time connecting to the same subnet ( unless firewall is on transparent mode), so what you can do on this case will be to use redundant interfaces ( one will be up, the other one will be on stand-by) so you will provide more redundancy to your network witch I think is what you are looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 18:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853525#M489385</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-09T18:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Single firewall with 2 core switches</title>
      <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853526#M489386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/5/2/72251-Senario2.JPG" class="jive-image" /&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;01.There are 4 wan links with different subnets ( ADSL,Internet Leased line, Customer 1,Custpmer-2)&lt;/P&gt;&lt;P&gt;02. All routers are connected via L2 switch to the firewall &lt;/P&gt;&lt;P&gt;03. The FW has 5 context licences (ASA5520)&lt;/P&gt;&lt;P&gt;04. FW is connected to the 2 coreswitches (Active and Stnby)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; My requirement is,&lt;/P&gt;&lt;P&gt;01. Is it possible to remove the L2 switch in&amp;nbsp; between the ASA and wan routers ( To avoid single point of failure)&lt;/P&gt;&lt;P&gt;02. If it can remove please advice how to config the ASA&lt;/P&gt;&lt;P&gt;03. How to config the ASA with contexts to route trafiic to the switches (Act/Stnby)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kawi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: KaWi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jan 2012 06:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853526#M489386</guid>
      <dc:creator>Kantha Wijesekara</dc:creator>
      <dc:date>2012-01-11T06:26:36Z</dc:date>
    </item>
    <item>
      <title>Single firewall with 2 core switches</title>
      <link>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853527#M489387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kantha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-So basically the two&amp;nbsp; routers are on the same broadcast domain than the ASA, the thing is that as soon as you remove the layer two switch you will need to use a separate interface to connect to each router, so then each interface will need to be on a different subnet ( let me know if that is possible).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- So if you can set up that scenario ( 2 subnets) as you know the ASA does not support PBR but as you know the destination for the customer´s branchs we can do configure this:&lt;/P&gt;&lt;P&gt;Route outside1 branch1_network&amp;nbsp; subnet_mask&amp;nbsp; Router1_ipaddress&lt;/P&gt;&lt;P&gt;Route outside1 branch2_network&amp;nbsp; subnet_mask&amp;nbsp; Router1_ipaddress&lt;/P&gt;&lt;P&gt;Route outside2 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Router2_address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3-Regarding the context configuration:&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808d2b63.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808d2b63.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.tech21century.com/cisco-asa-multiple-context-mode-%E2%80%93-configuring-virtual-firewalls-on-same-chassis/"&gt;http://www.tech21century.com/cisco-asa-multiple-context-mode-%E2%80%93-configuring-virtual-firewalls-on-same-chassis/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate if this post helps you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jan 2012 06:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-firewall-with-2-core-switches/m-p/1853527#M489387</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-11T06:38:30Z</dc:date>
    </item>
  </channel>
</rss>

