cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
623
Views
5
Helpful
3
Replies

Cisco ASA Multi context mode - Stretched DMZ

ohareka70
Level 3
Level 3

Hello,

I have two Cisco 5585 Firewalls across a stretched DMZ.  I was hoping to create high availability by creating the two firewalls into Multi context mode.  It failed miserably.  Don't know if it was a configuration issue or just a bad idea but had to roll back both firewalls to stand alone again.

Has anyone done this sort of project before?

Is their a simple way of doing this like using two load balancers instead?

I really just want to create high availability for the servers & applications on the DMZ off both firewalls.  Its a pity cisco firewalls dont just do HSRP or something like that.

Could i use routers to do this?

any ideas appreciated

Kevin

1 Accepted Solution

Accepted Solutions

You need to extend the LAN at layer 2.  You could buy a layer 2 circuit (preferably QinQ) form your service provider and let them do it.

If you have routers you could also built an L2TPv3 tunnel between the sites and do it yourself.

View solution in original post

3 Replies 3

Philip D'Ath
VIP Alumni
VIP Alumni

I have done it many times, using stretched VLANs between DC's.  Works fine.

I recommend having redundant layer 2 patches, to prevent the "split brain" issue.

And make sure you stretch the failover network between them as well.

What I want to do is have one subnet 192.168.180.x/24 running across two sites.  I already have the physical subnet in place but each side has a different gateway on the 192.168.180.x network otherwise is would have a loop

What I then tried to do was have the Cisco 5585 firewalls in Multi context mode so they would replicate across the subnet.  It seems to work ok for a few hours but then I had sync issues.

I just want to have high availability across the subnet for the servers but maybe I don't need to change the firewalls to be in multiple context mode

any ideas?

Maybe use load balancers instead - between the two firewalls?

You need to extend the LAN at layer 2.  You could buy a layer 2 circuit (preferably QinQ) form your service provider and let them do it.

If you have routers you could also built an L2TPv3 tunnel between the sites and do it yourself.

Review Cisco Networking for a $25 gift card