05-24-2022 02:50 AM - edited 05-24-2022 02:51 AM
Hi Alls,
I have a question when I try to connect 2 group of redundancy Firewall as picture below. I never try before. Is it possible to connect like picture and what I need to configure in both side?
Thanks in advance, and have a very nice day!
05-24-2022 04:58 AM
If this is a like a perimeter firewall pair and LAN/data centre pair sure, but i would recommend getting some switches in between and do not connect them directly.
While a number of potential problems/limitations can be pointed out with connecting them directly, if FW1 or FW2 active and standby interfaces are to be monitored, they would start exchanging heat beat packets. If those interfaces are directly connected to other firewall's interface there's a potential loss of such packets causing failover issues.
05-24-2022 06:50 PM
Hi @UdupiKrishna,
Thank for your reply.
Can I asking exactly how many switch we need to add between them? and Do you have any topic and document related to "heat beat packets"?
Have a nice day.
05-24-2022 07:02 PM
Logically two switches so that there's always connectivity should one of them fail. A trunk link between the switches
Here's a document - https://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/failover.html (refer section unit health monitoring)
05-24-2022 07:42 PM
hi @UdupiKrishna, thank for your support
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide