cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
633
Views
0
Helpful
2
Replies

Redundant ASA with two Switches

ahmad82pkn
Level 2
Level 2

Hi, i am working on some high availibility design for my campus network. i need little help.

Currently my 6509 is connected with 2xASA(Active/Standby)  that connect with a single outside switches(poitn of failure) and then internet router(point of failure).

we got another interner router with another ISP and did BGP multihomed and connected it with second outside switch and configured HSRP on it.

Now my question is can i connect Primary ASA outside interface with first outside switch  and  connect secondary ASA outside interface with second outside switch? ( is it that simple? ) all i want is in case primary outside switch go down, traffic move to second outside switch and then out to internet via second router.

Attached is diagram for more explanation

2 Replies 2

Reza Sharifi
Hall of Fame
Hall of Fame

Hi,

It should work fine.  You need to run HSRP or VRRP with a /28 or 29 between the 2 outside switches and the firewalls.  You also need a connection between the firewalls to be used as the active/stand-by heard beat.

HTH

Hello Reza,

Yes both Firewall already configured and connected via LAN base failover cable.

Outside switches are Layer 2, but i am planning to run HSRP on routers.

so with above clarification and my original question and my proposed diagram, i should be fine right?

more cautions since change is in main data center so want to avoid any downtime, though its been lucky for running since longs without hardware failure.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card