cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
490
Views
3
Helpful
1
Replies

Firewall interconnects

mohsin.khan
Level 3
Level 3

Need expert opinion on which one of below is considered as best practice and why...

     Option-1    

               RTR-1----ASA---- SW-1

                    \       /      \     /

                 |             |             |

                     /     \       /     \

               RTR-2----ASA----SW-2        

     Option-2   

               RTR-1----ASA---- SW-1

                 |             |             |

               RTR-2----ASA----SW-2

1 Reply 1

Jon Marshall
Hall of Fame
Hall of Fame

mohsin.khan@telenor.com.pk

Need expert opinion on which one of below is considered as best practice and why...

     Option-1    

               RTR-1----ASA---- SW-1

                    \       /      \     /

                 |             |             |

                     /     \       /     \

               RTR-2----ASA----SW-2        

     Option-2   

               RTR-1----ASA---- SW-1

                 |             |             |

               RTR-2----ASA----SW-2

Neither actually. You need L2 adjacency between the ASA interfaces and although you have that on the switch side you don't on the router side. It should be

RTR1 --  SW1 -- ASA1  -- SW2

  |             |          |             |

RTR2 -- SW3 -- ASA2  -- SW4

Jon

Review Cisco Networking for a $25 gift card