Connection Between Core and Firewall

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-26-2018 11:56 AM - edited 02-21-2020 08:17 AM
Dears,
Please find the attached
Please suggest when 6509 are in VSS mode how the connection should be. The access switch is connected to both core with Multi chassis Ether channel, ,,, the user traffic is hash in default algorithm of the port channel, src dst ip
how the traffic flow will be when the connection are according to the Diagram A and how the flows will be when it is according to the Diagram B
AND
Thanks
- Labels:
-
NGFW Firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-26-2018 12:03 PM
Is the FW are in Cluster mode Active / Active or Active / Standby? 2nd one give you more High availability in terms of failure scenarios.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-26-2018 01:23 PM
firewalls are in active / standby mode
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-26-2018 02:49 PM
Look at good CVD document, for your reference.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-27-2018 01:50 AM
If the ASA's are active/standby then in either scenario (diagram A or B) traffic would not be routed via the FW-B, if it is still standby/secondary. So in diagram A if the traffic originated on Core 2 the traffic would cross the link to Core 1 and then to the FW-A. In Diagram B ideally you'd configure the ASA's to be members of a port-channel, traffic would then go directly from Core 1 to FW-A or from Core 2 to FW-A. Diagram B is the better design.
HTH

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-29-2018 02:25 PM
Dears,
thanks to both of you and +5 to you both,
clustering is different concept than a active/standby or active/active.
thanks

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-01-2018 02:01 PM
