03-31-2020 02:21 AM
Dear All,
I am plannig to cluster two Cisco FPR2130-asa-k9 to maximize the througtput for my remote VPN users(Anyconnect).
Is it possible? I see that old Asa5520 with 9.1 doesn't support vpn if cluster is in place.
BR,
JF.
Solved! Go to Solution.
03-31-2020 04:39 AM
Clustering is not supported on Firepower 2130 appliances running ASA image.
04-01-2020 11:54 PM
Hi Cristian,
Thanks for your quick reply.
So also create a cluster should be possible, to perform VPN load balance?
04-02-2020 12:08 AM
Hi,
ASA Clustering is not supported on that specific HW, the 2100 series. VPN Load Balancing is supported. Here's some references to guide you:
Regards,
Cristian Matei.
03-31-2020 03:51 AM
Hi,
1. Are you speaking about Clustering for High Availability or about VPN Load Balancing?
2. Are you speaking about S2S VPN's or remote access VPN's?
Regards,
Cristian Matei.
03-31-2020 04:39 AM
Clustering is not supported on Firepower 2130 appliances running ASA image.
03-31-2020 05:33 AM
Thanks Marvin,
There are another way to load balance remote users VPN on the two 2130?
04-01-2020 11:41 AM
VPN Load Balancing.
04-01-2020 08:07 PM
Like @Cristian Matei said, VPN load balancing is the most common method for appliances with ASA image. (It's not supported on FTD image.)
Another method is round robin DNS.
If you have a load balancer or "application delivery controller (ADC)" like Citrix Netscaler or F5 BigIP you may be able to put your ASAs behind it and to load balancing on the ADC.
Also, depending on your deployment, Optimal Gateway Selection (OGS) is a potential option. That one is usually for organizations with their ASAs spread out in different locations geographically.
04-01-2020 09:38 PM
Hi,
@Marvin Rhoads Thanks for the additional solutions. As a general fact (from experience with OGS), unless you really have geographically dispersed VPN gateways (in which case OGS becomes an option to be considered), VPN Load Balancing is a much simpler and more functional/stable solution, with less headaches.
Regards,
Cristian Matei.
04-01-2020 10:49 PM
Hi Marvin,
Ok it is clear for me thank you.
But the 2130 that I own do not has a FTD Image, they are Fpr2130-Asa-k9 so ,should have "standard" Asa Image, is it true?
Bye
Igor.
04-01-2020 11:34 PM
Hi,
Correct, you run ASA on the 2100 HW. And all presented options are valid: VPN load balancing (configuration performed on the ASA), DNS based balancing (you would need a balancer in front of your ASA's), AnyConnect OGS (AnyConnect decides on which ASA will terminate the session).
Regards,
Cristian Matei.
04-01-2020 11:54 PM
Hi Cristian,
Thanks for your quick reply.
So also create a cluster should be possible, to perform VPN load balance?
04-02-2020 12:08 AM
Hi,
ASA Clustering is not supported on that specific HW, the 2100 series. VPN Load Balancing is supported. Here's some references to guide you:
Regards,
Cristian Matei.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide