06-18-2018 12:07 PM - edited 02-21-2020 07:53 AM
Hi am working on a design where i have two ASA firewalls in Active and Passive state and for Gre over IPsec connection i need one router in front of these firewalls .Can any one provide me config or tell what is best way to design this connectivity.
ASA 5525 (Active) ------
Cisco 4331
ASA 5525(Standby)------
So i have two connection from both firewalls on Cisco 4331.
Thanks
06-18-2018 05:43 PM
take two ports on your ISR and connect and outside interface of the ASAs to each of the ports.
Run a link between the two ASA's directly as a HA
06-18-2018 08:15 PM
Thank you Dennis, but what will be configuration on ISR side and ASA on those ports ,as i am using firewall as active and standby.
should i use /30 pool on both links i don’t think that will work as firewalls are active/Standby.
any suggestions?
06-18-2018 08:45 PM
the subnet between ASA's and ISR is not really that relevant, but it needs to contain at least 3 host addresses. from the ISR you can do a default route pointing to the outside of each of your ASA, with an sla track statement. you could decidedc to used dynamic routing to allow failover for when the active ASA fails over to the standby.
06-19-2018 01:01 AM
06-19-2018 08:57 AM
I am doing all of my configurations through the GUI ASDM. (I know, some people really love the CLI even for configurations, but I don’t. I am using it only for troubleshooting issues.) For this lab I am using a Cisco ASA 5506-X with ASA version 9.5(1), while ASDM is version 7.5(1). In my lab, I have a default route to ISP 1 (gi1/1) and a different connection to ISP 2 (gi1/2). There is no route to ISP 2 in the routing table. I want that each user generated http/https traffic is routed to ISP 2, while anything else is still traversing through ISP 1 to the Internet.
My recommendation: https://www.
06-19-2018 09:05 PM
andrew, are you spamming us or is there something useful in that link?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide