09-19-2017 07:26 AM - edited 02-21-2020 06:19 AM
I am in a process of deploying ASA 5516x HA cluster ( Active/Standby), I need to connect this cluster to another FW HA cluster ( not sure about the vendor) with another organisation.
I was given a network design physical connectivity as below,
Cisco ASA primary -outside interface --->> Third party FW1 outside interface (primary)
Cisco ASA secondary -outside interface ---->> Third party FW2 outside interface (secondary)
Third party FW 1 and FW2 also acting as a cluster. All the firewalls need to physically connect without using an intermediate switch.
Can this work , if during the ASA failover?
My understanding is that all the FWs needs to have a mesh connection or use intermediate switch and implement L2 domain in outside interfaces.
Any suggestions please?
Solved! Go to Solution.
09-19-2017 07:58 PM
Hello,
Physically direct connect is required in some kind of clusters as well. Or they just want to eliminate any point of failure between Firewall.
What I find more interesting is that this setup suggest that they want to build a high redundant cluster of firewall but mixing up vendors. This is something I dont get it.
Let´s imagine if Active ASA fail, Standby ASA takes over. On the other Side nothing has change and Active Third part Firewall is still Active. As per your design, this Active Third part Firewall does not have physical connection with ASA standby and Active ASA is down.
If that happen, communitacation between both organization will be broken.
09-19-2017 07:58 PM
Hello,
Physically direct connect is required in some kind of clusters as well. Or they just want to eliminate any point of failure between Firewall.
What I find more interesting is that this setup suggest that they want to build a high redundant cluster of firewall but mixing up vendors. This is something I dont get it.
Let´s imagine if Active ASA fail, Standby ASA takes over. On the other Side nothing has change and Active Third part Firewall is still Active. As per your design, this Active Third part Firewall does not have physical connection with ASA standby and Active ASA is down.
If that happen, communitacation between both organization will be broken.
09-20-2017 03:04 AM
Hi Flavio
Thank you for your response. I thought the same way and advised customer to make a cluster connection. I wanted verify my suggestion with other experts.
thank you again
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide