cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


176
Views
0
Helpful
0
Replies
Highlighted
Beginner

Managing Multiple Contexts on a pair of ASA 5516

Hello, I'm trying to solve a problem (or to try to undertand if this problem has a solution) regarding multiple contexts on a pair of ASA-5516.

 

This pair of ASA should be used to connect a single CISCO 3580 (let's call it VSS) to 3 different sites (each of them with unspecified active/passive firewall pairs, let's call them FW1, FW2, FW3)

These pairs are completely independent, so it would be necessary to be able to react to separate failover of these remote pairs.

My first idea was to use multiple context, with an active/active configuration, so that in case of a failure of a remote active (es. FW3), the context 3 would failover to the 2nd unit.

Anyway, reading the documentation, it seems to me that it is impossible to make the 3 contexts completely independent, as the tracking is done on failover groups, not on contexts, and that a maximum of 2 failover groups are available on a cluster.

Is this correct, that I can't just define 3 completely independent contexts ? 

Is there any alternative solution to this problem, taking into account that I have to use these 5516 ? 

 

Thanks for your advices and opinions on this matter

Regards

CreatePlease to create content
Content for Community-Ad
FusionCharts will render here