05-04-2011 06:11 AM - edited 03-04-2019 12:15 PM
Hi All,
I need your confirmation on this set-up that i'll be attaching. I am planning to implement this set-up, ECMP from the Core to the Internet Edge with ASA. From the edge default route will be injected pointing to the Internet and route redistribution will be employed. The diagram is attached and please do browse over it. Application is VOIP (SIP). This is done to do load balancing on the ISP.
05-04-2011 06:38 AM
disregard ecmp via eigrp, ecmp via OSPF i mean.
05-04-2011 01:01 PM
Hello Joseph,
an ASA can have two different next-hops out the SAME interface, because it is primarily a firewall and not a router.
So it can have two next-hops out the same interface but you need to deploy L2 switches in the middle to achieve this or you need to use SVIs on the L3 switches and to have a single broadcast domain spanning on the two ASA of the HA pair and on the two multilayer switches.
see
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/ip.html#wp1118237
>> Load sharing on the security appliance is possible only for multiple next-hops available using single egress interface. Load sharing cannot share multiple egress interfaces.
after that you can have two OSPF neighbors out an interface
so you need to review the proposed design accordingly
Hope to help
Giuseppe
07-18-2011 10:37 AM
thanks giuseppi, would the set-up introduce jitter or asymetric routing problem>?? can you please give me idea or suggested design to do this....
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide