<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5545X in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032524#M780602</link>
    <description>&lt;P&gt;Sheraz,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for the fast reply. This is the link that I am using that is making me second guess using our existing 9300 and or 2960's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#id_65978" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#id_65978&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Look at the "ASA Services Module, IOS, and Switch Compatibility" Section...&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2020 19:33:24 GMT</pubDate>
    <dc:creator>TW80CJ5</dc:creator>
    <dc:date>2020-02-19T19:33:24Z</dc:date>
    <item>
      <title>ASA 5545X</title>
      <link>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032502#M780600</link>
      <description>&lt;P&gt;We are thinking about clustering the ASA 5545X with another exact build of the 5545X. We currently have the Cisco Catalyst 9300 Switch in our topo and would want to use that for the port-channeling / load balancing. We have some 2960's available too. Will these switches support the ASA cluster?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 18:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032502#M780600</guid>
      <dc:creator>TW80CJ5</dc:creator>
      <dc:date>2020-02-19T18:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5545X</title>
      <link>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032508#M780601</link>
      <description>&lt;P&gt;I am using 2x5525 cluster with 3850 as port-channel and its working fine. so to answer your question yes you can create a cluster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes 9300 and 2960 can do cluster. switches only need to be a port-channel rest all the magic on cluster is happening on firewalls.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 18:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032508#M780601</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-02-19T18:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5545X</title>
      <link>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032524#M780602</link>
      <description>&lt;P&gt;Sheraz,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for the fast reply. This is the link that I am using that is making me second guess using our existing 9300 and or 2960's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#id_65978" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#id_65978&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Look at the "ASA Services Module, IOS, and Switch Compatibility" Section...&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 19:33:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032524#M780602</guid>
      <dc:creator>TW80CJ5</dc:creator>
      <dc:date>2020-02-19T19:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5545X</title>
      <link>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032544#M780603</link>
      <description>&lt;P&gt;Cisco 9300 is a good choice instead of 2960.&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa95/configuration/general/asa-95-general-config/ha-cluster.html" target="_self"&gt;here&lt;/A&gt;&amp;nbsp; is the link you need to look. in the document cisco specifically mentioned n Catalyst 3750-X Cisco IOS software versions earlier than 15.1(1)S2, the cluster unit did not support connecting an EtherChannel to a switch stack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;9300 is good chose. do you need to know the process how to create a cluster?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 20:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032544#M780603</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-02-19T20:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5545X</title>
      <link>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032587#M780604</link>
      <description>&lt;P&gt;I am always open to a config!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for the help and clarification!!!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 21:14:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032587#M780604</guid>
      <dc:creator>TW80CJ5</dc:creator>
      <dc:date>2020-02-19T21:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5545X</title>
      <link>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032624#M791214</link>
      <description>&lt;P&gt;&lt;STRONG&gt;STEP1 CREATE ETHERCHANNEL ON SWITCH FIRST&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;SWITCH_CONFIG&lt;BR /&gt;interface range gig1/0/1-2,gig1/0/4-4&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;swtichport trunk all vlan add 10-12&lt;BR /&gt;channel-group 1 mode active&lt;BR /&gt;no shut&lt;BR /&gt;!&lt;BR /&gt;interface port-channel1&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;swtichport trunk all vlan add 10-12&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;STEP2&lt;/STRONG&gt;&lt;BR /&gt;ASA1&lt;BR /&gt;mode multi&lt;BR /&gt;!&lt;BR /&gt;interface gig1/3&lt;BR /&gt;no shut&lt;BR /&gt;!&lt;BR /&gt;cluster interface-mode spanned force&lt;BR /&gt;!&lt;BR /&gt;cluster group CLUSTER-ASA&lt;BR /&gt;local-unit ASA1&lt;BR /&gt;cluster-interface gig1/3 ip 192.168.100.1 255.255.255.0&lt;BR /&gt;priority 1&lt;BR /&gt;!&lt;BR /&gt;mtu cluster 9000&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;STEP3&lt;/STRONG&gt;&lt;BR /&gt;ASA2&lt;BR /&gt;mode multi&lt;BR /&gt;!&lt;BR /&gt;interface gig1/3&lt;BR /&gt;no shut&lt;BR /&gt;!&lt;BR /&gt;cluster interface-mode spanned force&lt;BR /&gt;!&lt;BR /&gt;cluster group CLUSTER-ASA&lt;BR /&gt;local-unit ASA2&lt;BR /&gt;cluster-interface gig1/3 ip 192.168.100.2 255.255.255.0&lt;BR /&gt;priority 2&lt;BR /&gt;!&lt;BR /&gt;mtu cluster 9000&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;STEP4&lt;/STRONG&gt;&lt;BR /&gt;ASA1&lt;BR /&gt;cluster group CLUSTER-ASA&lt;BR /&gt;enable!&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;STEP5&lt;/STRONG&gt;&lt;BR /&gt;ASA2&lt;BR /&gt;cluster group CLUSTER-ASA&lt;BR /&gt;enable as-slave&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Give it some time asa will form the cluster.&lt;/P&gt;
&lt;P&gt;once the cluster is up and running. "show cluster info"&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;STEP6&lt;/STRONG&gt;&lt;BR /&gt;!&lt;BR /&gt;interface man1/1&lt;BR /&gt;no shut&lt;BR /&gt;!&lt;BR /&gt;interface gig1/1&lt;BR /&gt;no shut&lt;BR /&gt;channel-group 1 mode active&lt;BR /&gt;!&lt;BR /&gt;interface gig1/2&lt;BR /&gt;no shut&lt;BR /&gt;channel-group 1 mode active&lt;BR /&gt;!&lt;BR /&gt;interface port-channel1&lt;BR /&gt;port-channel span-cluster&lt;BR /&gt;!&lt;BR /&gt;interface port-channel1.10&lt;BR /&gt;vlan 10&lt;BR /&gt;!&lt;BR /&gt;interface port-channel1.11&lt;BR /&gt;vlan 11&lt;BR /&gt;!&lt;BR /&gt;interface port-channel1.12&lt;BR /&gt;vlan 12&lt;BR /&gt;!&lt;BR /&gt;admin-context admin&lt;BR /&gt;!&lt;BR /&gt;context admin&lt;BR /&gt;!&lt;BR /&gt;allocate-interface man1/1&lt;BR /&gt;allocate-interface port-channel1.10&lt;BR /&gt;allocate-interface port-channel1.11&lt;BR /&gt;allocate-interface port-channel1.12&lt;BR /&gt;config-url disk0:admin.cfg&lt;BR /&gt;!&lt;BR /&gt;context admin&lt;BR /&gt;!&lt;BR /&gt;ip local-pool asa-pool 192.168.20.70-192.168.20.71&lt;BR /&gt;!&lt;BR /&gt;interface man0/0&lt;BR /&gt;management-only&lt;BR /&gt;nameif mgmt&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.20.69 255.255.255.0 cluster-pool asa-pool&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and so on......&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 22:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5545x/m-p/4032624#M791214</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-02-19T22:27:20Z</dc:date>
    </item>
  </channel>
</rss>

