cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Bookmark
|
Subscribe
|
1839
Views
0
Helpful
6
Replies

Two ASA's Doing Different Functions Yet Failover

If we have two internet connections, one for each ASA, but use the ASA’s for different purposes can we still have them fail over.  For example, O365 traffic goes out one asa on one connection and traffic that backups data to the cloud go out the other asa connected to the other ISP?

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

Is this ASA part of Active / Standby or  setup as standalone ?

if this standalong you can do that, based on PBR how you route the traffic.

 

Do you have any high level network digram.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

We currently have one ISP and the two ASAs in HA mode - active standby

We were wondering if the ASAs could still failover if For example, O365 traffic goes out one asa on one connection and traffic that backups data to the cloud go out the other asa connected to the other ISP? 

Nice, in that case, it is easy for you to setup PBR on ASA, select which path to go. ( addon you can also take advantage of ISP failover options).

 

https://www.networkstraining.com/cisco-asa-policy-based-routing-pbr/

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Perhaps I am not understanding something correctly. I believe that the original poster tells us that the 2 ASA are configured as an active/standby failover pair. In this configuration one ASA forwards traffic and the other ASA does not forward traffic. The original poster also says they want O365 traffic to use one ASA while some other traffic uses the second ASA. But both ASA actively forwarding traffic is incompatible with active/standby HA. If you want both ASA to actively forward traffic you need to remove the HA configuration.

HTH

Rick

I was in the impression that the user aware of its Active / Standby. I do not believe that user intention not to break HA I guess. 

 

I have made a suggestion only based on the existing arrangements.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

As I said, perhaps I am not understanding correctly something in the discussion. But it seems to me that one objective is to maintain the HA failover capability of the 2 ASAs and another objective is for both ASAs to actively forward traffic. Perhaps the original poster can provide some clarification?

HTH

Rick