<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2 distribution switches to 1 ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924046#M5520</link>
    <description>&lt;P&gt;For this scenario it doesn't matter if you have one ASA or two in HA. In most cases I would just ignore this "problem" when both switches are directly colocated and have a direct link (typically a channel) between each other. It's just one switched hop more than the optimal path. Or you have to build your distribution as a VSS/VPC or stack. There you can use EtherChannels to both devices.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Sep 2019 16:38:58 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2019-09-13T16:38:58Z</dc:date>
    <item>
      <title>2 distribution switches to 1 ASA</title>
      <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3923984#M5504</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've built a reasonable large topology in GNS3 to show use of a variety of layer 2 and 3 technologies, with just a touch of ASA or enough to demonstrate ASA basics and setup of a site-to-site VPN. As a result and most importantly because I can't really afford any more CPU cycles(!), I have a single ASA connecting my layer 2 block to the edge router running BGP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SingleASA_2Distro.png" style="width: 390px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/44916i3D841D057D38D449/image-size/large?v=v2&amp;amp;px=999" role="button" title="SingleASA_2Distro.png" alt="SingleASA_2Distro.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way in which I can connect the ASA to the two distribution switches running HSRP for two VLANs? As I say, I just don't want to undo my hard work and time by pushing GNS any more.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read a few responses to a similar question whereby a simple switch between the distros and ASA is the solution, presumably keeping things layer 2 between the new switch and the distribution switches?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I achieve this and also ensure that traffic will be returned to the current HSRP active device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:29:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3923984#M5504</guid>
      <dc:creator>mrjdh</dc:creator>
      <dc:date>2020-02-21T17:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: 2 distribution switches to 1 ASA</title>
      <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924017#M5507</link>
      <description>&lt;P&gt;You can configure a redundant interface on the ASA and add one member-interface connecting to SW1 and one member-interface connecting to SW2. The redundant interface also can have sub interfaces for all your needed VLANs. But as ASA and the Switch don't share any information which switch is HSRP-active, you could have a non-optimal traffic flow.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 15:52:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924017#M5507</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2019-09-13T15:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: 2 distribution switches to 1 ASA</title>
      <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924021#M5510</link>
      <description>Thanks Karsten. Is there any way around the no-knowledge of the active switch? What would you do in this scenario, keeping only the 1 ASA?</description>
      <pubDate>Fri, 13 Sep 2019 15:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924021#M5510</guid>
      <dc:creator>mrjdh</dc:creator>
      <dc:date>2019-09-13T15:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: 2 distribution switches to 1 ASA</title>
      <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924028#M5513</link>
      <description>You may be working on resilient network design.&lt;BR /&gt;&lt;BR /&gt;You may refer this&lt;BR /&gt;&lt;A href="https://www.802101.com/cisco-asa-failover-redundant-interfaces-catalyst-hsrp-and-power/amp/" target="_blank"&gt;https://www.802101.com/cisco-asa-failover-redundant-interfaces-catalyst-hsrp-and-power/amp/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Unfortunately emulator GNS3/EVE-NG with ASAv does not support redundant interface as i know.&lt;BR /&gt;And i want to know the status for the IPSEC VPN issue which you posted earlier.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Fri, 13 Sep 2019 16:20:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924028#M5513</guid>
      <dc:creator>bhargavdesai</dc:creator>
      <dc:date>2019-09-13T16:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: 2 distribution switches to 1 ASA</title>
      <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924036#M5516</link>
      <description>Hi bhargavdesi,&lt;BR /&gt;Thank you for the reply - I haven't forgotten about your VPN reply, I'm going to be testing it in the next couple of hours!</description>
      <pubDate>Fri, 13 Sep 2019 16:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924036#M5516</guid>
      <dc:creator>mrjdh</dc:creator>
      <dc:date>2019-09-13T16:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: 2 distribution switches to 1 ASA</title>
      <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924043#M5519</link>
      <description>Thank and do let me know if you need further help on that.&lt;BR /&gt;And i hope the link will give you good ideas about latest query&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Fri, 13 Sep 2019 16:29:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924043#M5519</guid>
      <dc:creator>bhargavdesai</dc:creator>
      <dc:date>2019-09-13T16:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: 2 distribution switches to 1 ASA</title>
      <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924046#M5520</link>
      <description>&lt;P&gt;For this scenario it doesn't matter if you have one ASA or two in HA. In most cases I would just ignore this "problem" when both switches are directly colocated and have a direct link (typically a channel) between each other. It's just one switched hop more than the optimal path. Or you have to build your distribution as a VSS/VPC or stack. There you can use EtherChannels to both devices.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 16:38:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924046#M5520</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2019-09-13T16:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: 2 distribution switches to 1 ASA</title>
      <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924067#M5522</link>
      <description>That's great - thanks for another reply Karsten, much appreciated. I love this community!</description>
      <pubDate>Fri, 13 Sep 2019 16:57:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924067#M5522</guid>
      <dc:creator>mrjdh</dc:creator>
      <dc:date>2019-09-13T16:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: 2 distribution switches to 1 ASA</title>
      <link>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924092#M5523</link>
      <description>You are welcome!&lt;BR /&gt;</description>
      <pubDate>Fri, 13 Sep 2019 17:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-distribution-switches-to-1-asa/m-p/3924092#M5523</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2019-09-13T17:29:59Z</dc:date>
    </item>
  </channel>
</rss>

