cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1956
Views
0
Helpful
6
Replies

Redundant connection between switch stack and single ASA

jpeterson6
Level 2
Level 2

I've got a single ASA 5510 running v8.2 and my client wants it to directly connect into two 3750 switches (both members of one stack) for redundancy.

It is my understanding that Etherchannel was introduced to ASA in 8.4, but upgrading is not an option at this time due to the amount of changes required.

What is the best way to go about this? I'm thinking something to do with IP SLA on the 3750 side, but what about the ASA side? Would HSRP be the better option?

Thanks.

1 Accepted Solution

Accepted Solutions

Hi,

   Easy way to do this without upgrading OS 8.4 on ASA(which needs checking hardware first). Just try redundant interface on ASA to acting as active/standby and yes,it can connect across C3750 stack. Just read how redundant interface works: http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html#wp1045838

HTH,

Toshi

View solution in original post

6 Replies 6

Hi,

   Easy way to do this without upgrading OS 8.4 on ASA(which needs checking hardware first). Just try redundant interface on ASA to acting as active/standby and yes,it can connect across C3750 stack. Just read how redundant interface works: http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html#wp1045838

HTH,

Toshi

Thanks once again (You helped me in another thread).

One thing about that link that concerns me though under Physical Interface Guidelines

You cannot add a physical interface to the  redundant interface if you configured a name for it. You must first  remove the name using the no nameif command.

Caution: If you are using a physical interface already in  your configuration, removing the name will clear any configuration that  refers to the interface.

Is this true? This ASA has previous configuration on it. What configurations will be cleared? I assume all NAT and ACLs on the inside interface.. anything else I should worry about?

Hi,

I hate to say this but yes seems you need a bit downtime for modification. But this feature is good if you cannot go for etherchannel on 8.4.

Toshi

Sent from Cisco Technical Support iPhone App

Gotcha.

What needs to be configured on the switch end? Just two switchport access interfaces on the same VLAN and that's it?

Hi,

You are right. Thats what you have to do on c3750.

Toshi

Sent from Cisco Technical Support iPhone App

Worked great. Thanks again.

Review Cisco Networking for a $25 gift card