cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3216
Views
0
Helpful
9
Replies

Using Firewall ethernet ports as HSRP

Kevin
Level 1
Level 1

Hi Guys,

 

Lets say i have two routers to be put in redundancy mode, can i use firewall as layer 2 switch link for HSRP link? 

 

 

1 Accepted Solution

Accepted Solutions

You are correct, you will need a switch between the two routers and the firewall as all three devices need to share the same layer 2 VLAN. You only need a layer 2 switch. Regards, Mike

View solution in original post

9 Replies 9

Mike Williams
Level 5
Level 5
Yes, if you are using a firewall with an integrated switch, such as an ASA 5505. If it only has routed ports, such as any other ASA model, then the answer is no. In any event, it's not recommended. A firewall is meant as a security device, not as a switch. Regards, Mike

Hi Mike,

 

Can i just use layer 2 switch in between router and firewall to enable the HSRP? 

 

Or it must be layer 3?

 

Thanks.

 

 

Firewall at L3 can be connected to two switches for HSRP. gateway for firewall should be pointing to the virtual ip configured for HSRP...

How about connection from:

 

Router (HSRP) --- Switch --- Firewall ?

In order for router to have HSRP i need to have a switch right? 

You are correct, you will need a switch between the two routers and the firewall as all three devices need to share the same layer 2 VLAN. You only need a layer 2 switch. Regards, Mike

Thanks mike and bala for your advices. 

Will any l2 switch between the router and the firewall work ? 

 

I have a spare 5port 1gbit switch but is not cicso brand. Can i use it to connect the hsrp routers and the asa firewall ? 

 

Thanks 

As long as you aren't doing VLAN tagging, any switch will do. You just need to be able to bridge layer 2 ethernet.

Regards,

Mike

Hi Mike, 

 

thanks alot for the quick reply. 

And should i have any concerns regarding bottleneck using the cheap netgear GS105E ? 

Review Cisco Networking for a $25 gift card