09-15-2015 05:29 PM - edited 03-11-2019 11:36 PM
We are looking to purchase at least two Cisco 6500 series switches with the latest sup engines as-well-as the Cisco ASA service modules.
My question is, could we have the all of the following in the same box and place this setup at the perimeter?
Thank you
Frank
09-17-2015 04:11 AM
Hi,
I think BGP with full routing table is not officially supported but depends on the resources on the box so should work.
The only other thing is the Anyconnect support on Multiple Context is not supported but is in on roadmap for future version:- https://tools.cisco.com/bugsearch/bug/CSCsm17507/?reffering_site=dumpcr
And without Multiple context , you would not be able to use the Active/Active Failover.
Thanks and Regards,
Vibhor Amrodia
09-17-2015 09:39 AM
Hi Vibhor,
Thank you
For clarity - I envision this setup like this - the 6500 Sup720 with maximum DRAM would run BGP to interface with the ISP and hold the full internet routing table. BGP would dynamically announce the Default-Network into OSPF and OSPF would announce our internal LANs to BGP. OSPF would run on each virtual context within the ASA SM. OSPF would support our internal LANs. BGP would not be needed on the ASA SM. - I think I stated this incorrectly in my original message.
Are you saying we WILL need to employ the ASA SM multi-context mode to support an active/active setup?
Thank you
Frank
09-17-2015 09:59 AM
Hi,
Yes , For Active/Active Failover , you need to be in Multiple Context.
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/91336-pix-activeactive-config.html
Also , to be clear on the requirement:-
EIGRP is supported in multi-context mode. But EIGRP instances cannot form adjacency with each other across shared interfaces because inter-context exchange of multicast traffic is not supported. Yes, ASA will form neighbor ship with other peers.
Thanks and Regards,
Vibhor Amrodia
09-19-2015 07:26 AM
Hi Vibhor,
This is how I envision this setup,
QUESTION: Does this seem correct?
Thank you for your assistance
Frank
09-19-2015 05:17 PM
Hi,
I don't see any problem with this requirement.
I just wanted to make sure that you don't have any peering between the ASA contexts itself.
Thanks and Regards,
Vibhor Amrodia
09-20-2015 08:55 AM
Thank you
Frank
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide