05-04-2011 09:31 PM - edited 03-11-2019 01:29 PM
Hi Forumer's
Just seeking idea on how to design on redundant firewall design
1. branch firewall got dual uplink, which normal time is using primary line connect to HQ. If connection to HQ fail, then will swap to secondary link for ensure connection resume.
2, failover between HQ and DRC, anything need to mention for this part?
3. what's the best way to design this topology?
Hopefully with your idea can spakle me to drill deeper, thanks
Noel
05-05-2011 11:43 AM
Hi,
SLA monitoring will help you out on this one. If the primary route fails, VPN will try to establish on the secondary Link. If it is a site to site tunnel you can add a secondary peer so it can establish the VPN tunnel.
Here is the configuration for SLA monitor.
Hope this helps.
Mike
05-05-2011 11:58 PM
Hi, thanks for the reply.
Just wondering can ASA support on MPLS? because the WAN strucuture is running on MPLS.
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide