cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1248
Views
5
Helpful
3
Replies

Good HA Design?

CiscoBrownBelt
Level 6
Level 6

See attachment of topology lab.

So I have configured the 2 ASA for HA/failover. Now because I have redundant links from both ASAs to both csr1000 routers, I am looking for guidance on best technologies/design to use. 

Can I configure the g2 and 3 interfaces for a layer 3 BDI (its IOS-XE) and configure the pair in some type of HA setup?

What about interface g0/0 and 0/1 on the FW? 

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

Personally i would termniate all the interface to Nexus Switch (considering Nexus have high availability)

 

Logically Seperate each side with Different VLAN. For ASA  HA , the link you need be in the same broacast domain.

 

example below high level.

 

Cisco ASA Failover Active Standby

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Which interfaces are you referring to? The ASA terminate upstream to a Nexus then to the Routers?

is the real environment ot Lab ? your diagram does not show the path.

 

if you can make Physical and Logical it would nice to suggest.

 

My suggestion, Use Nexus as Core - Create a VLAN , connect router and ASA router in Stick mode suggest way. you can also do inline but if the interfaces fails, you will have down time,

 

 

 

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help