07-18-2019 07:02 PM
See attachment of topology lab.
So I have configured the 2 ASA for HA/failover. Now because I have redundant links from both ASAs to both csr1000 routers, I am looking for guidance on best technologies/design to use.
Can I configure the g2 and 3 interfaces for a layer 3 BDI (its IOS-XE) and configure the pair in some type of HA setup?
What about interface g0/0 and 0/1 on the FW?
07-18-2019 11:39 PM
Personally i would termniate all the interface to Nexus Switch (considering Nexus have high availability)
Logically Seperate each side with Different VLAN. For ASA HA , the link you need be in the same broacast domain.
example below high level.

=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
07-23-2019 08:37 AM
07-23-2019 09:12 AM
is the real environment ot Lab ? your diagram does not show the path.
if you can make Physical and Logical it would nice to suggest.
My suggestion, Use Nexus as Core - Create a VLAN , connect router and ASA router in Stick mode suggest way. you can also do inline but if the interfaces fails, you will have down time,
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide