01-04-2013 08:57 AM - edited 03-11-2019 05:43 PM
Hello All,
We are thinking of introducing ASA's into our setup instead of using FWSM for our firewalls with our 6500. Currently we use multiple contexts with the FWSM, as we provide hosting services for multiple clients and want them behidn their own firewall. My question is how can we make this happen with an ASA. Since with the FWSM we use the backplane of the 6500 and SVI's for all interfaces between them. For example if we have 20 clients what will be the ideal setup for us to use with an ASA. If we can infact use mutiple contexts how can we? Is there a way we can maybe bundle all the ports in the ASA into the 6500 as a layer two trunk port and continue to use SVIs to manage all the clients. All advice is greatly appreciated and thanks so much in advance!
Solved! Go to Solution.
01-04-2013 09:23 AM
Hi,
You can use the ASA for the same purpose as the current FWSM.
I have also migrated firewall enviroments from old FWSMs to new ASAs.
Multiple Context mode
Connectivity to the Core
I suggest referring to the configuration guide of the of software level you are getting for the ASA firewalls for specific information.
You can find them here
http://www.cisco.com/en/US/products/ps6120/products_installation_and_configuration_guides_list.html
If you have some specific question, please ask
Please rate if you have found the information to be helpfull
- Jouni
01-04-2013 09:23 AM
Hi,
You can use the ASA for the same purpose as the current FWSM.
I have also migrated firewall enviroments from old FWSMs to new ASAs.
Multiple Context mode
Connectivity to the Core
I suggest referring to the configuration guide of the of software level you are getting for the ASA firewalls for specific information.
You can find them here
http://www.cisco.com/en/US/products/ps6120/products_installation_and_configuration_guides_list.html
If you have some specific question, please ask
Please rate if you have found the information to be helpfull
- Jouni
01-04-2013 09:40 AM
For information about the different ASA models
Check the following documents
ASA 5500 Series (Includes the 5585-X models too)
ASA 5500-X Series (Models that will replace the previous 5500 series)
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/at_a_glance_c45-701635.pdf
If I didnt miss something it seems the datasheet for the newer models doesnt for some reason list the supported amount of the Security Contexts.
Using the latest software version on the ASA will bring some new features available to be used in Multiple Context Mode like L2L VPN under the Security Contexts which wasnt previously possible. It also enables using Routing Protocols in Multiple Context Mode etc.
- Jouni
01-04-2013 09:54 AM
Jouni as always much thanks for your assistance!! I will use all the info you've provided in planning a mgration over from our FWSMs to ASAs. Thanks again!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide