11-05-2018 02:00 PM - edited 03-08-2019 04:33 PM
I have 2 ASA 5516 firewalls connected to 2 4500X VSS clusters over a LACP interface. There is a transit L3 vlan between the firewall that includes the inside interface on the ASA and is the default route on the 4500X's. Currently, whenever I define a new L3 VLAN on the switch I define a static route back to it on the inside interface on the firewall. No routing protocols are used anywhere. HSRP is used between the switches/vlans. Would there be any benefit to setting up OSPF on the firewall and switch? Other than keeping me from manually defining a route for each new VLAN does it really fix what isn't broken?
11-05-2018 02:10 PM
Depends on how big your network ? please explain the network devices in the network.
11-05-2018 02:53 PM
2 asa 5516X with 2 4500X VSS pairs with about 12 2960X connecting to the 4500X's. L2 VLANS on the 2960X's, L3 VLANS on the 4500X's with VACLs between VLANs. IP routing enabled on 4500Xs. Traffic routing to the ASA is Internet or DMZ bound.
11-05-2018 03:05 PM
Personally Static is good enough, until you see special requirement dynamically route some traffic and you want to traffic engineering with IGP. then move to OSPF.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide