07-15-2011 09:19 AM - edited 03-07-2019 01:14 AM
I've got a single ASA 5510 running v8.2 and my client wants it to directly connect into two 3750 switches (both members of one stack) for redundancy.
It is my understanding that Etherchannel was introduced to ASA in 8.4, but upgrading is not an option at this time due to the amount of changes required.
What is the best way to go about this? I'm thinking something to do with IP SLA on the 3750 side, but what about the ASA side? Would HSRP be the better option?
Thanks.
Solved! Go to Solution.
07-15-2011 09:34 AM
Hi,
Easy way to do this without upgrading OS 8.4 on ASA(which needs checking hardware first). Just try redundant interface on ASA to acting as active/standby and yes,it can connect across C3750 stack. Just read how redundant interface works: http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html#wp1045838
HTH,
Toshi
07-15-2011 09:34 AM
Hi,
Easy way to do this without upgrading OS 8.4 on ASA(which needs checking hardware first). Just try redundant interface on ASA to acting as active/standby and yes,it can connect across C3750 stack. Just read how redundant interface works: http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html#wp1045838
HTH,
Toshi
07-15-2011 06:44 PM
Thanks once again (You helped me in another thread).
One thing about that link that concerns me though under Physical Interface Guidelines
You cannot add a physical interface to the redundant interface if you configured a name for it. You must first remove the name using the no nameif command.
Caution: If you are using a physical interface already in your configuration, removing the name will clear any configuration that refers to the interface.
Is this true? This ASA has previous configuration on it. What configurations will be cleared? I assume all NAT and ACLs on the inside interface.. anything else I should worry about?
07-15-2011 07:05 PM
Hi,
I hate to say this but yes seems you need a bit downtime for modification. But this feature is good if you cannot go for etherchannel on 8.4.
Toshi
Sent from Cisco Technical Support iPhone App
07-15-2011 08:53 PM
Gotcha.
What needs to be configured on the switch end? Just two switchport access interfaces on the same VLAN and that's it?
07-16-2011 04:11 AM
Hi,
You are right. Thats what you have to do on c3750.
Toshi
Sent from Cisco Technical Support iPhone App
07-16-2011 02:31 PM
Worked great. Thanks again.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide