cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
768
Views
10
Helpful
6
Replies

Connection Between Core and Firewall

adamgibs7
Level 6
Level 6

Dears,

 

Please find the attached

 

Please suggest when 6509 are in VSS mode how the connection should be. The access switch is connected to both core with Multi chassis Ether channel, ,,, the user traffic is hash in default algorithm of the port channel, src dst ip

 

how the traffic flow will be when the connection are according to the Diagram A and how the flows will be when it is according to the Diagram B 

AND

 

 

Thanks

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

Is the FW are in Cluster mode Active / Active  or Active / Standby?  2nd one give you more High availability in terms of failure scenarios.

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

firewalls are in active / standby mode

Hi,
If the ASA's are active/standby then in either scenario (diagram A or B) traffic would not be routed via the FW-B, if it is still standby/secondary. So in diagram A if the traffic originated on Core 2 the traffic would cross the link to Core 1 and then to the FW-A. In Diagram B ideally you'd configure the ASA's to be members of a port-channel, traffic would then go directly from Core 1 to FW-A or from Core 2 to FW-A. Diagram B is the better design.

HTH

Dears,

thanks to both of you and +5 to you both,

clustering is different concept than a active/standby or active/active.

thanks

Peter Koltl
Level 7
Level 7

IMG_0327_Po.png

Review Cisco Networking for a $25 gift card