[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Cisco PIX/ASA Firewall Failover

Posted on 2006-11-14
9
Medium Priority
?
1,287 Views
Last Modified: 2013-11-16

PIX/ASA 1----------------Catalyst Switch 1----------------Cisco Router 1
      |                                      |                                          |
PIX/ASA 2----------------Catalyst Switch 2----------------Cisco Router 2


I have the above setup in my network to achieve network redundancy.  Both firewalls have failover configured, and firewall 1 is the active one.  Both routers are running HSRP, and router 1 is the active one.  My question is:

1. If Catalyst Switch 1 fails, will failover happen to firewall 2 and router 2?  Can traffic still go from firewall to router (or the other way round)?
0
Comment
Question by:hoggiee
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 17938337
Most likely not unless there is catastrophic failure of the switch - full power off or all ports down.
That's the only way that the PIX would get an interface down event. Same on the router.
However, an interface down event does not necessarily create a failover situation for the ASA or the router.
My advise is to use a dynamic routing protocol such as OSPF between the two routers and the ASA's. Run the ASA's in Active/Active mode and let the routing determine the best route. No need for HSRP on the routers either.
BGP between the two routers and the 2 ISP links.

0
 
LVL 79

Accepted Solution

by:
lrmoore earned 2000 total points
ID: 17938357
You can also use object tracking on the PIX/ASA failover pair for a failover route and plug one interface from each ASA into each switch.
Dual ISP links:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml
0
 

Author Comment

by:hoggiee
ID: 17943301
That means the above setup will not achieve full redundancy isit? If switch 1 fails and no failover, there will be a communication breakdown?
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:hoggiee
ID: 17943400
The link that you have given for the object tracking on the PIX/ASA is just fastastic.  Could provide alternative solution for outgoing Internet access.  Can I use that for incoming Internet access, so that outside users can still access to my web server, and also emails can still reach my Exchange server via the backup Internet link?(if I have a backup DNS server which resolves my webserver and exchange server to the set of IP addresses given by ISP 2).
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 2000 total points
ID: 17946303
>If switch 1 fails and no failover, there will be a communication breakdown?
Yep. Sorry.
Routers behave a certain way
Switches behave a certain way
PIX/ASA behaves a certain way
None of them handle failover the same way.

Best alternative to having dual switches is to have everything plugged into just one switch with a second "cold spare" racked and ready. Power it up and manually move all the cables to the spare switch in event of failover. No manual intervention is ideal, so the next best thing is dynamic routing protocols that don't care or they compensate for loss of data path. The switch in the middle is just a path and can't participate in the dynamic decision making.

Fortunately, the switch is probably the component that is least likely to fail.
0
 

Author Comment

by:hoggiee
ID: 17962241
ok. one last question..... the object-tracking feature in PIX/ASA only available in version 7.0 and above?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 17964615
Correct. ASA only comes with 7.x,  existing PIX can be upgraded to 7.x
0
 

Author Comment

by:hoggiee
ID: 17970010
Thanks.

"My advise is to use a dynamic routing protocol such as OSPF between the two routers and the ASA's. Run the ASA's in Active/Active mode and let the routing determine the best route"

My understanding from ASA guides is that Active/Active failover mode can only be implemented in multiple context mode.  And in multiple context mode, some features might not be available. e.g. VPN, dynamic routing.  In this case, how true the above statement is?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 17971411
I forgot about the multiple context mode requirement...

OK, back to the drawing board, but you can see that making total redundancy is a difficult thing to do.
1 x high availability switch in between the PIX Active/Standby pair and the routers. I'd still use OSPF though.
0

Featured Post

Tech or Treat!

Submit an article about your scariest tech experience—and the solution—and you’ll be automatically entered to win one of 4 fantastic tech gadgets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
As managed cloud service providers, we often get asked to intervene when cloud deployments go awry. Attracted by apparent ease-of-use, flexibility and low computing costs, companies quickly adopt leading public cloud platforms such as Amazon Web Ser…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question