cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
402
Views
4
Helpful
3
Replies

firewall question

k.adath2015
Level 1
Level 1

Hi

I have the below plan  for dc firewall , 

In asa side  will be trunk and  the nexus side it will be vpc(asa will be in a cluster) 

What are the pros and cons ?

Since vpc  does not block any link how the  traffic wil flow   ?. 

From the DC  leaf switch   a server ( vlan 10 ) sending traffic ,  it  choose the link to the  right aggregator switch    same  time a server in vlan 20 , traffic will be going through the left aggregator switch . 

And  from the asa(trunk )how the traffic  flows back ?

Thanks

3 Replies 3

Francesco Molino
VIP Alumni
VIP Alumni

Hi

I assume that when you're talking about cluster you mean ASA cluster feature and not cluster word (commonly used) to represent a failover active/active or active/standby.

Advantages of cluster vs failover group, it's that all ASA will be grouped in 1 logical device and aggregate traffic throughput. You can have a limit of firewall numbers depending on the hardware (16 x 5585 and 2 x 5500X if I remember good). To implement Cluster, there is a specific license you need to purchase.

Failover is more high availability and Cluster is for scalability.

For traffic flow, I won't re-write all explanation but there is a very good presentation done by Cisco for CiscoLive.

Globally, ASA will have some roles to make sure you'll have a stateful connection. 

I attach this presentation to this post.

The load balancing for traffic is based on different protocols:

  • ECLB (equal cost load balancing – etherchannel)
  • PBR (policy based routing)
  • ECMP (L3 equal cost multipath)

Based on ASA roles (owner, Director, Forwarder), if you have asymmetric routing, within the cluster, there is an algorithm to always redirect the traffic to the firewall that received the SYN (Owner). Again explaining that in few words, is quite complex but you'll see everything interesting in the PDF attached to make your decision.

I don't know your exact design, but if throughput isn't a concern, and if you want to have different firewall process for different vrf (for example) I would go with active/active firewall. If your concern is throughput then Cluster is the best way to go.

Let me know if you have more questions.

Thanks

PS: Please don't forget to rate and mark as correct answer if this answered your question.


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Hi

It Would be great help , if you provide a quick and generic design

asa cluster and vpc

Thanks

Hi

Here are ASA designs with vPC:

http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Data_Center/VMDC/ASA_Cluster/ASA_Cluster/ASA_Cluster.pdf

Thanks

PS: Please don't forget to rate and mark as correct answer if this answered your question.


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question