Solved

Alternative to buying and implementing a third Cisco ASA for failover.

Posted on 2010-09-09
2
515 Views
Last Modified: 2012-05-10
Hi,
We are currently looking at implementing a PIX to ASA upgrade on our network. There are two ISL's in place (alternate provider) and will connect to the new ASA's individually. We also require a failover mechanism between both firwalls and an active connection from both to the
our DR site. The option currently being looked at is to implement a third ASA. The DR site is firewalled and if third ASA is not put in place there will only be a link from the DR site to one local firewall. This will not satifsfy failover requirements as if the firewall linked to DR goes down, how will fail over take place? Are there other options available apart from third firewall, hardware must be cisco. Thanks in advance.
0
Comment
Question by:Joz05
2 Comments
 
LVL 4

Accepted Solution

by:
mpickreign earned 500 total points
ID: 33637249
If I am understanding you correctly. You should be able to do this with two ASA 5510s (or above).

The ASA5510 and above will handle multiple internet connections and can be configured to automatically switch if on connection goes down.  I would configure one ASA with both internet connections and the connection to the DR, then configure the second ASA as a hot-standby in the event of hardware failure.
0
 

Author Closing Comment

by:Joz05
ID: 33637451
Thanks
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
New Rules on SourceFire ASAx 5 44
Asymmetric Routing (Firewall) 3 71
clean-up rule netscreen firewall 3 82
E-mail alerts from Cisco ASA Firepower 3 47
Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
Skype is a P2P (Peer to Peer) instant messaging and VOIP (Voice over IP) service – as well as a whole lot more.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now