cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
844
Views
0
Helpful
2
Replies

Switch between Cisco ASA for failover

network_user
Level 1
Level 1

Hello,

I see Cisco recommends that you should connect a dedicated switch between two ASAs for configuring LAN failover and stateful failover, instead of connecting a cable directly between the two ASAs. Does someone know what is the advantage of putting a switch in between them??

Thank you.

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

The main advantage is that if you use a direct cable and one of the failover interfaces fails then the other interface on the other firewall goes down as well so it can make troubleshooting difficult.

If you use a switch and one interface fails the other is still up because it is connected to the switch.

It does not necessarily have to be a dedicated switch in terms of only using that switch for the failover link, as long as the switch you use is not overutilised and is not heavily oversubscribed.

Jon

View solution in original post

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

The main advantage is that if you use a direct cable and one of the failover interfaces fails then the other interface on the other firewall goes down as well so it can make troubleshooting difficult.

If you use a switch and one interface fails the other is still up because it is connected to the switch.

It does not necessarily have to be a dedicated switch in terms of only using that switch for the failover link, as long as the switch you use is not overutilised and is not heavily oversubscribed.

Jon

Thanks Jon!

Review Cisco Networking for a $25 gift card