cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1590
Views
0
Helpful
12
Replies

BGP on Cisco Firewall Cluster

Network Pro
Level 1
Level 1

Hello

 

Scenario - I have two ISP's terminating on Cisco Firewalls (Active/Passive) - is it possible to run BGP between the two ISP's and the pair of Cisco Firewall (failover mode) - I am not how the iBGP will work between them as they both share the same LAN address right?

12 Replies 12

Hi

If your firewalls support BGP you could configure eBGP peerings with the ISP, they will have different AS. I think you want to do something like:

https://supportforums.cisco.com/t5/wan-routing-and-switching/bgp-multihoing-with-firewall-cluster/td-p/2877188

 

Hope it is useful

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Thanks for the quick reply - so i would not require iBGP peering since its a cluster, right?

You are welcome, 

That is correct, basically the cluster is seen as one firewall, the backup firewall has the same configuration like the primary.

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Deepak Kumar
VIP Alumni
VIP Alumni

Hi, 

If you will configure the ASA in Active-passive mode, then the Passive firewall will not give you the option to configure any BGP or link address (only HA links). The passive firewall will synchronize active firewall configuration. 

Only you have to think about how to configure BGP with Both ISP and make transit area. 

This link will helpful :

https://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/23675-27.html

 

 

Regards,

Deepak Kumar

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

hi

 

wouldnt i be able to configure both links on Primary Firewall? because its a cluster if primary dies wont secondary box take over?

Hi, 

Your network design will be like:

 

ISP 1 ---->                    -----ISP1------>     Active Firewall   ------->LAN (Inside)

                                     -----ISP2------->

                   Switch L2 

                                    ------ISP1------>       Passive Firewall -----> LAN (Inside>

ISP 2 ---->                 -----ISP2------->

 

 

If any of ISP or Firewall will down.. another device will take over.

 

Regards,

Deepak Kumar

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

That is correct, each firewall must have connection with each ISP, now the suggestion is use VLANs between the ISP and the Firewalls through the L2 switch displayed by Deepak, it will provide scalability to your infrastructure. 

 

For example:

               SWITCH

ISP 1 --- VLAN 10 --- Firewall 1

ISP 2 --- VLAN 20 --- Firewall 1

 

ISP 1 --- VLAN 10 --- Firewall 2

ISP 2 --- VLAN 20 --- Firewall 2

 

I suggest have 2 switches or a stack of switches to avoid point of failures.

 

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Yes correct this is what i was thinking too

 

are you saying this wwill work right? any issues of this? only thing is that there will be NO iBGP peer, correct?

Yes, You correct no iBGP peer between firewalls.

 

Some other suggestions for L2 switch as

Disable the CDP/LLDP

Enable Spanning tree portfast (on ports which are connected to firewalls and ISP)

 

 

Regards,

Deepak Kumar

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

The Cluster will be seen as one firewall running 1 BGP only. Something like:

 

               ISP1

             /

firewall
firewall 

             \  

                ISP2

 

But each firewall will have 2 peerings one to each ISP through the VLANs created. 

 

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Yep Thanks everyone

You are welcome

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<
Review Cisco Networking products for a $25 gift card