cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
539
Views
0
Helpful
1
Replies

Connecting 2 ASA's to one Edge router (layer 3 question)

joe.hall
Level 1
Level 1

Hello and thanks for your assistance.

My company has purchased a second ASA for failover reasons and I'm needing to attach it to my core router (ASR 1001)

Currently I'm running the connection between my ASA and my Core as a /19   ie. ASA-10.10.10.2/19 -- ASR-10.10.10.1/19

I know the 2nd interface on the ASR will need to be on a differant network segment then the first connection (10.10.10.1/19)

What would be the best way to segment this out with out breaking up my /19?

Run /30 segments for each interface?

Use a VLan ?

I don't want to use up my Internet routable IP's on /30 segments.

Attached diagram

Thanks for the help

1 Reply 1

Andrej Zverev
Level 1
Level 1

If your ASA will work as active/standby you need them to be in one network segment.

Take a look into this topic https://supportforums.cisco.com/message/3726701, i think this is your solution, but be aware of BDI restrictions and limitations.