01-28-2017 08:27 AM
Hi
I have the below plan for dc firewall ,
In asa side will be trunk and the nexus side it will be vpc(asa will be in a cluster)
What are the pros and cons ?
Since vpc does not block any link how the traffic wil flow ?.
From the DC leaf switch a server ( vlan 10 ) sending traffic , it choose the link to the right aggregator switch same time a server in vlan 20 , traffic will be going through the left aggregator switch .
And from the asa(trunk )how the traffic flows back ?
Thanks
01-28-2017 11:56 AM
Hi
I assume that when you're talking about cluster you mean ASA cluster feature and not cluster word (commonly used) to represent a failover active/active or active/standby.
Advantages of cluster vs failover group, it's that all ASA will be grouped in 1 logical device and aggregate traffic throughput. You can have a limit of firewall numbers depending on the hardware (16 x 5585 and 2 x 5500X if I remember good). To implement Cluster, there is a specific license you need to purchase.
Failover is more high availability and Cluster is for scalability.
For traffic flow, I won't re-write all explanation but there is a very good presentation done by Cisco for CiscoLive.
Globally, ASA will have some roles to make sure you'll have a stateful connection.
I attach this presentation to this post.
The load balancing for traffic is based on different protocols:
Based on ASA roles (owner, Director, Forwarder), if you have asymmetric routing, within the cluster, there is an algorithm to always redirect the traffic to the firewall that received the SYN (Owner). Again explaining that in few words, is quite complex but you'll see everything interesting in the PDF attached to make your decision.
I don't know your exact design, but if throughput isn't a concern, and if you want to have different firewall process for different vrf (for example) I would go with active/active firewall. If your concern is throughput then Cluster is the best way to go.
Let me know if you have more questions.
Thanks
PS: Please don't forget to rate and mark as correct answer if this answered your question.
01-30-2017 12:08 AM
Hi
It Would be great help , if you provide a quick and generic design
asa cluster and vpc
Thanks
01-30-2017 05:25 AM
Hi
Here are ASA designs with vPC:
http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Data_Center/VMDC/ASA_Cluster/ASA_Cluster/ASA_Cluster.pdf
Thanks
PS: Please don't forget to rate and mark as correct answer if this answered your question.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide