11-12-2012 08:12 AM - edited 03-11-2019 05:22 PM
Hello everyone,
Currently in our environment we have have two buildings with an ASA 5520 in each and a core stack of 3750's in each building. I am currently working on a network segmentation project and am thinking of adding another stack of 3750's in each building to add more redundancy to our network. This will allow our access layer switches to have a trunk to each stack and prevent an outage if one of the links or stacks were to go down.
My question is how I would set this up on the ASA end of things while using a common subnet and HSRP on the 3750's. I understand how to use HSRP and STP on the switches to achieve this on the 3750 end of things. I saw you can do etherchannel on the ASA with 8.4 but how does that work in a failover situation?
Also, if the design I am proposing is incorrect or if you have a better suggestion please let me know.
Thanks,
Solved! Go to Solution.
11-12-2012 08:58 AM
Seems to fit on a regular ASA failover scenario,
It is also possible to have virtual firewalls and do load balance between them. For example, having ASA primary and ASA secondary. Enable Virtual ASA1 and Virtual ASA2.
The ASA primary can have Virtual ASA 1 as primary and Virtual ASA 2 as failover.
The ASA secondary can have Virtual ASA 1 as backup and Virtual ASA 2 as primary.
11-12-2012 08:58 AM
Seems to fit on a regular ASA failover scenario,
It is also possible to have virtual firewalls and do load balance between them. For example, having ASA primary and ASA secondary. Enable Virtual ASA1 and Virtual ASA2.
The ASA primary can have Virtual ASA 1 as primary and Virtual ASA 2 as failover.
The ASA secondary can have Virtual ASA 1 as backup and Virtual ASA 2 as primary.
11-12-2012 11:35 AM
Hello Melendres,
Thank you for your reply. Your link does help. I just spoke with our team and we are actually scrapping the dual stacks in each building and just going with one stack in each building. This way we can keep it simple and always add on other stacks in the future if we need to.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide