02-20-2023 10:56 AM
I’ve got 2 ASA’s side by side and it’s connected via IPsec - it works great
Since they in the same site - I’d like to use a physical connection (faster/secure) and link the 2 firewalls and connect the internal networks on both ASA’s
So what is the best way to do it ?
Iam thinking of giving 1 interface on each an ip on the same subnet and static route ?
Please advise
thanks
02-20-2023 10:59 AM - edited 02-20-2023 11:01 AM
@machine23 you can physically connect the interfaces, configure an IP address in the same network, configure routing (static/dynamic) and configure the access control list to pertmit/deny traffic accordingly.
Another option, if they are physically in the same location, you could make them an HA failover pair for resilency and just configure the 2 networks on different interfaces.
02-20-2023 11:19 AM
Thanks Rob for the input … I will try that
02-20-2023 01:50 PM
So I connected them and when adding routes it says route already exists ( from the site to site I think )
HA seems the-logical option ..
For HA connect both internal networks to the active and configure the other as standby ?
02-20-2023 01:53 PM - edited 02-20-2023 01:55 PM
@machine23 it depends what static route you are referring to. You would not need a static route for the outside interface of the other ASA, it's directly connected. You need static routes for the internal networks. It would be helpful to provide this information so we know what you've configured.
Yes, you could configure as Active/Standby, with each network on a separate interface. Example - https://integratingit.wordpress.com/2016/08/12/configuring-cisco-asa-activestandby-failover/
02-20-2023 02:12 PM
yes I’m trying to add internal static routes, I’ve got some full tunnel vpn to setup and I’ll get the Config over … thanks for the help very much appreciated
02-20-2023 02:00 PM
If you share your network topology it is better
02-20-2023 11:20 AM
connect internal network to both ASA you need to run ASA HA
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide