cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
439
Views
0
Helpful
4
Replies

Firewall Configuration Suggestion

rdotson
Level 1
Level 1

I have 2 5585's that I want to install and connect to 2 different ISP's ( or in this case 2 different TLS connections to Verizon).  I have no way of port channeling the two TLS connectons except at the ASA itself.  The TLS connections are the the inside network. The outside connections will go to a switch that is managed by a group where I can have them port channeled if necessary.

I was thinking about clustering, but to make things simple for some of the other staff that will be managing these firewalls when I am out, I've decided to make them Active/Standby.

My question is, because of the two separate TLS connections, is there any reason I can't just make these Active/Standby just as though they would normally be if connected to a switch?                 

level3.jpg

4 Replies 4

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

Forgive me my ignorance but what does the TLS stand for?

So these 2 links are the links to your LAN network?

Remember that the ASAs "inside" links have to be connected on the LAN side on L2 so that the ASAs can monitor eachother for the Failover. Or in the case of subinterface each of them have to be connected also L2 at the remote LAN end of the network.

- Jouni

TLS is Transparent Lan Service.  Basically it is a L2 Ethernet Connection from 2 different sources. 

Yes that is our (inside) LAN network.

My configuration will be a single context with no subinterfaces.

Hi,

Sounds to me that the setup should work just fine.

Last year I did a migration for a customer from a Dual FWSM to Dual ASA5585-X SSP-20.

Basically we host the ASAs on our datacenter and provide the customer 2 direct 1Gbps links to their site through 2 different physical routes. ASA is Active/Standby.

They have their own L3 Switch Stack on their site as the core which they manage. Though in this situation there are multiple subinterfaces on the single physical link but otherwise the setup would seem to me to be the same type as yours.

-  Jouni

Thank you Jouni, I'll give it a try.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: