Two ASA's Doing Different Functions Yet Failover
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-23-2020 08:41 AM - edited 06-23-2020 08:42 AM
If we have two internet connections, one for each ASA, but use the ASA’s for different purposes can we still have them fail over. For example, O365 traffic goes out one asa on one connection and traffic that backups data to the cloud go out the other asa connected to the other ISP?
- Labels:
-
Network Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-23-2020 09:16 AM
Is this ASA part of Active / Standby or setup as standalone ?
if this standalong you can do that, based on PBR how you route the traffic.
Do you have any high level network digram.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-23-2020 10:29 AM
We currently have one ISP and the two ASAs in HA mode - active standby
We were wondering if the ASAs could still failover if For example, O365 traffic goes out one asa on one connection and traffic that backups data to the cloud go out the other asa connected to the other ISP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-23-2020 01:09 PM
Nice, in that case, it is easy for you to setup PBR on ASA, select which path to go. ( addon you can also take advantage of ISP failover options).
https://www.networkstraining.com/cisco-asa-policy-based-routing-pbr/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-27-2020 10:04 AM
Perhaps I am not understanding something correctly. I believe that the original poster tells us that the 2 ASA are configured as an active/standby failover pair. In this configuration one ASA forwards traffic and the other ASA does not forward traffic. The original poster also says they want O365 traffic to use one ASA while some other traffic uses the second ASA. But both ASA actively forwarding traffic is incompatible with active/standby HA. If you want both ASA to actively forward traffic you need to remove the HA configuration.
Rick
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-27-2020 12:55 PM
I was in the impression that the user aware of its Active / Standby. I do not believe that user intention not to break HA I guess.
I have made a suggestion only based on the existing arrangements.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-27-2020 01:50 PM
As I said, perhaps I am not understanding correctly something in the discussion. But it seems to me that one objective is to maintain the HA failover capability of the 2 ASAs and another objective is for both ASAs to actively forward traffic. Perhaps the original poster can provide some clarification?
Rick
