I am not clear what you mean when you tell us about two ASA. Are you telling us that they operate as a failover pair or that they operate as two independent firewalls?
I did a project for a customer where there were two routers each with a connection to an ISP. We ran a dynamic routing protocol between the two routers and the ASA firewall pair. Each router advertised its routes to the ASA and if one outside route failed then all traffic used the surviving outside route. I would think this approach could work for you.
HTH
Rick
HTH
Rick
Learn, share, save
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.