09-16-2011 03:39 AM - edited 03-11-2019 02:25 PM
Hi Guys
First of all excuse me for my bad drawing, I need some help with ASA design.
I have two Cisco ASA 5585 which are connecting to two Nexus 7K.
I looked at one design and it seems I can make Redundant interfaces on ASA and put two physical interfaces (Link1-1/1-2) into it however the down side I can see is it will utilize one link out of 4 at one time. As per my understanding if I make redundant interface on ASA 1 and put 1-1/1-2 into it only one link would be active at one time. This will force Nexus2 to send all traffic to Nexus 1 in order to reach ASA.
Ideally I want a solution where both switches could send traffic straight to Active Firewall and incase of failure both links to standby firewall.
Diagram attached.