<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 supporting dual connections in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143465#M878068</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with kylerossd, sla monitor with rtr tracking is the better solution.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Jan 2009 21:42:47 GMT</pubDate>
    <dc:creator>josephp</dc:creator>
    <dc:date>2009-01-06T21:42:47Z</dc:date>
    <item>
      <title>ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143457#M878057</link>
      <description>&lt;P&gt;I have a quick question;&lt;/P&gt;&lt;P&gt;if one was to enable HSRP on two routers (same subnet address), could a ASA support/uplink the dual connections  from both routers?  &lt;/P&gt;&lt;P&gt;correct me if I'm wrong, but wouldn't one have to enable a dynamic routing protocol on the ASA in order to support this type of solution?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:33:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143457#M878057</guid>
      <dc:creator>ksvy_ksvy</dc:creator>
      <dc:date>2019-03-11T14:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143458#M878058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not quite sure what you mean. Is there a switch between the ASA and the 2 routers or do you mean connect into 2 interfaces on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HSRP is not intended for utilising both links so it's not entirely clear what you mean.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 21:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143458#M878058</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-01-06T21:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143459#M878059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're running HSRP across two interfaces, you would just point the ASA to the virtual address. Is this how your setup is?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;&lt;FONT size="3"&gt;&lt;/FONT&gt;&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;  INTERNET&lt;/P&gt;&lt;P&gt; |.......| &lt;/P&gt;&lt;P&gt;RTR.... RTR&lt;/P&gt;&lt;P&gt; |_______| &amp;lt;--HSRP running here&lt;/P&gt;&lt;P&gt;.....|&lt;/P&gt;&lt;P&gt;....ASA&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ignore the dots, I used them to fix the ACSII art.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 21:08:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143459#M878059</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-01-06T21:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143460#M878060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon, sorry, yes, a switch will be connecting both routers and firewall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 21:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143460#M878060</guid>
      <dc:creator>ksvy_ksvy</dc:creator>
      <dc:date>2009-01-06T21:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143461#M878063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way ASA primary/failover works is quite different from having 2 switches connecting to external routers, for HSRP.. I havent seen any scenario to have HSRP between external firewall and routers.. The issue here is, there is no layer 2 forwarding between the ASA's, unlike switches which can forward information over the trunk ! Hence.. have two static routes, or as u said, a routing protocol running between the ASA and router, to forward L3 traffic...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failure can happen in the following ways:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Incase the first router goes down, ASA's interface goes down, and the traffic is flapped onto the failover firewall in a stateful way.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Incase the link on the primary router goes down the ASA primary will forward traffic to the primary router.. primary router should be connected back to back with failover router, to forward traffic through the secondary link... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) same applies on the failure of ASA's too ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. all the best..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 21:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143461#M878063</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2009-01-06T21:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143462#M878064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still a little unclear as to your question. As Collin says you can just allocate the ASA into the same subnet and then point the ASA route to the HSRP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am i misunderstanding your question ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 21:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143462#M878064</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-01-06T21:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143463#M878066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your second connection just for redundancy or do you have your own ASN and both routers are BGP peers to your ISPs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have 2 different external networks I would use ip sla and tracking statements. Then apply the track to the defualt route so it can be removed when the ip sla is no longer true.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 21:27:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143463#M878066</guid>
      <dc:creator>kylerossd</dc:creator>
      <dc:date>2009-01-06T21:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143464#M878067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it is just a single ASA, and a switch inbetween, then it makes sense to run HSRP on the routers.. as Jon said, you can point the default gateway on the ASA, to the VIP of the routers..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there should be some L2 connectivity between the HSRP neighbors, for the keepalives to flow.. since you have a layer 2 switch, it is very much possible.. as per my previous post, if you have the routers, directly connected to two different ASA's, then it would have been difficult, and L3 routing would have been the only solution...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 21:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143464#M878067</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2009-01-06T21:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143465#M878068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with kylerossd, sla monitor with rtr tracking is the better solution.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 21:42:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143465#M878068</guid>
      <dc:creator>josephp</dc:creator>
      <dc:date>2009-01-06T21:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143466#M878069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SLA with RTR tracking is a good solution, but basically complicates the whole setup ! Even if he has to run BGP, let it terminate on the external routers, and internally there can be a local route to reach the LAN, through the firewall.. Basically the routers can have a back-to-back connection to decide where to forward/receive packets from internet, through BGP or any other means.. The firewall's responsibility is just to forward the traffic onto a particular router, designated primary, which can be achieved thro simple HSRP !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my 2 cents... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 21:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143466#M878069</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2009-01-06T21:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143467#M878070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kyle, nope, this will be just an HSRP from both router's inside leg to ASA ... &lt;/P&gt;&lt;P&gt;no true dual ISP honing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 22:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143467#M878070</guid>
      <dc:creator>ksvy_ksvy</dc:creator>
      <dc:date>2009-01-06T22:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143468#M878071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So what happens when the primary HSRPs internet connection dies? It is still advertising the mac address of the gateway to the ASA and your dead in the water.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It gets even worse if the connection doesn't go down. Your CE routers copper is up but thier fiber is down your sitting there UP/UP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 22:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143468#M878071</guid>
      <dc:creator>kylerossd</dc:creator>
      <dc:date>2009-01-06T22:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143469#M878072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;true, but I think the network people were thinking only router failure, not ISP &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that'll be a fault in their design ... but I will remind them, thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 22:29:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143469#M878072</guid>
      <dc:creator>ksvy_ksvy</dc:creator>
      <dc:date>2009-01-06T22:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143470#M878073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem, Good luck!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 22:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143470#M878073</guid>
      <dc:creator>kylerossd</dc:creator>
      <dc:date>2009-01-06T22:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143471#M878074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kyle.. ISP redundancy has to be taken care at the router level.. when we speak about multihoming, we might need more than a rtr command to make it work.. The solution that we were referring would take care of the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) if the primary HSRP internet connection dies, packets would be forwarded to the primary router from FW, through HSRP VIP.. the primary router can run IBGP or any dynamic routing protocol to forward the traffic to the back up router, through a dedicated backtoback connection.. &lt;/P&gt;&lt;P&gt;2) if the primary router fails, HSRP will take care of alternate routing thro secondary router..&lt;/P&gt;&lt;P&gt;3) If the Ethernet doesnt go down, and the link remains up/up, BGP reachability on the primary router will go down, and an alternate path, through IBGP will be available thro secondary router.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all these will be considered only if multihoming is necessary.. This design is more from the WAN router point of view, than the firewall.. I think the firewall should do more of packet filtering, IPS etc, and do very less routing.. whats say ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing to offend your design.. it is a good one, but the scenario here is different i guess..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2009 00:49:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143471#M878074</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2009-01-07T00:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 supporting dual connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143472#M878075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because in EDGE design you don't what firewall get involve with a lot of routing you just need default gateway for your firewalls. So HSRP will provide you one redundant default gateway and then you can take care of routing and ISP redundancy in route level with BGP and one internal routing protocol.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2009 15:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-supporting-dual-connections/m-p/1143472#M878075</guid>
      <dc:creator>m_zabetian</dc:creator>
      <dc:date>2009-01-07T15:57:22Z</dc:date>
    </item>
  </channel>
</rss>

