cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
548
Views
0
Helpful
2
Replies

Redundant interface on transparent mode

kohsei.kadohno
Level 1
Level 1

Hello,

I have a question about transparent mode firewall by ASA5510.

I want to connect 3 circuit as inside and primary / backup outside.

====

interface Ethernet0/0

   nameif inside

   security-level 100

interface redundant 1

  member-interface Ethernet 0/1
  member-interface Ethernet 0/2
  nameif outside

  security-level 0

====

But I could not find the command in several document that forces the active when the interface becomes available (like preempt command).

Can ASA5510 force the active interface?

Best Regards,

Kohsei,

1 Accepted Solution

Accepted Solutions

Nagaraja Thanthry
Cisco Employee
Cisco Employee

Hello,

If I understand you correct, you have connected Ethernet 0/1 to one ISP and Ethernet 0/2 to another ISP. Unfortunately, the Redundant interface configuration is not intended to support such scenario. When the second interface takes over the active role, it will stay active until it goes down. The Redundant interface feature is introduced to increase the reliability of the ASA connections. If my above assumption is correct, I guess the best option would be to use a hub/switch between the ISP devices and the ASA.

Hope this helps.

Regards,

NT

View solution in original post

2 Replies 2

Nagaraja Thanthry
Cisco Employee
Cisco Employee

Hello,

If I understand you correct, you have connected Ethernet 0/1 to one ISP and Ethernet 0/2 to another ISP. Unfortunately, the Redundant interface configuration is not intended to support such scenario. When the second interface takes over the active role, it will stay active until it goes down. The Redundant interface feature is introduced to increase the reliability of the ASA connections. If my above assumption is correct, I guess the best option would be to use a hub/switch between the ISP devices and the ASA.

Hope this helps.

Regards,

NT

Thanks a lot for the quick reply.

Yes, there are two ISPs in outside area, and these CE routers are configured same network segment on LAN side.

I will recommend other design for client.

Thanks again,

Kohsei,

Review Cisco Networking for a $25 gift card