10-11-2011 10:18 AM - edited 03-11-2019 02:36 PM
Hello,
I see Cisco recommends that you should connect a dedicated switch between two ASAs for configuring LAN failover and stateful failover, instead of connecting a cable directly between the two ASAs. Does someone know what is the advantage of putting a switch in between them??
Thank you.
Solved! Go to Solution.
10-11-2011 10:49 AM
The main advantage is that if you use a direct cable and one of the failover interfaces fails then the other interface on the other firewall goes down as well so it can make troubleshooting difficult.
If you use a switch and one interface fails the other is still up because it is connected to the switch.
It does not necessarily have to be a dedicated switch in terms of only using that switch for the failover link, as long as the switch you use is not overutilised and is not heavily oversubscribed.
Jon
10-11-2011 10:49 AM
The main advantage is that if you use a direct cable and one of the failover interfaces fails then the other interface on the other firewall goes down as well so it can make troubleshooting difficult.
If you use a switch and one interface fails the other is still up because it is connected to the switch.
It does not necessarily have to be a dedicated switch in terms of only using that switch for the failover link, as long as the switch you use is not overutilised and is not heavily oversubscribed.
Jon
10-12-2011 12:16 PM
Thanks Jon!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide