Network design questions - Layer 3 switches w/ ASAs
Posted on 2010-11-17
I am preparing an upgrade to our network, we have 2 x ASA 5510 Sec Plus devices, and 2 x Cisco 3560 L3 switches.
I am planning on doing Active/Passive with the ASAs at the edge, however, I'm worried about interVLAN routing on the layer 3 switches as far as ACL management. I want to use the 3560s as the default gateway (HSRP) for all the equipment behind in order to use wire speed transfers between VLANs. ACL management on the ASA is infinitely easier to manage than on the L3 switches. I'll need 2 sets of ACLs (which will be mostly the same since it is multi-tenant)... does anyone have any advice on this configuration?