cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
540
Views
0
Helpful
1
Replies

How server traffic is routed between tierd ACE and ASA?

gwhuang5398
Level 2
Level 2

I have a two tier application services in the data center as following:

Internet -- ASA outside FW -- ACE for front end web servers -- ASA inside FW -- ACE for back end servers

The design is outside FW filters Internet access to front end web servers, and inside FW filters front end servers to back end servers. My question is: for each tier of servers, should their default gateway on respective ASA FW or the ACE load balancer?

Is there a design guide for this scenario?

Thanks

 

 

1 Reply 1

Kanwaljeet Singh
Cisco Employee
Cisco Employee

Hi,

The default gateway can be on ASA or ACE. If it is on ASA, you would need to NAT the traffic so that return traffic also goes through the ACE or you will have asymmetric routing. If ACE is the DGW, you don't need NAT. Some useful links for design:

http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Data_Center/ACE_FWSM.html#wp1000603

http://www.cisco.com/c/en/us/products/collateral/application-networking-services/ace-4710-application-control-engine/guide_c07-572616.html

Regards,

Kanwal

Note: Please mark answers if they are helpful.

Review Cisco Networking for a $25 gift card