Solved

multihome ASA

Posted on 2011-09-26
6
340 Views
Last Modified: 2012-08-14
What would be the best way to set up a ASA multihomed to two 6509's for failover? The links coming from the asa will pass through the 6509s via L2 only, no SVI's on the 6509s. or below it either. So basically the outside interface ties into the edge while the inside interfaces and dmz's would tie directly into the pair of 6509's.
0
Comment
Question by:chipsch
  • 3
  • 2
6 Comments
 
LVL 18

Expert Comment

by:jmeggers
ID: 36601405
You may be able to do redundant interfaces on the ASA, but I think the better choice is to configure the 6509s as a virtual switch and the ASA links as an Etherchannel (introduced in 8.4(1)).  You would have to make sure your 6500s can support VSS (see http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps9336/prod_qas0900aecd806ed74b.html).  The information on Etherchannel on the ASA is at http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/interface_start.html#wp1329030
0
 

Author Comment

by:chipsch
ID: 36601429
Great suggestion but we can not run VSS due to supervisor limitations. My sales pitch didn't quite work as soon as the dollar amount was seen, hehe. Any other ideas? I have not been able to find anything out there. If they supported 802.1w it would be to easy but they do not.
0
 
LVL 7

Accepted Solution

by:
Ironmannen earned 500 total points
ID: 36715121
Then redundant interfaces are your solution: Cisco ASA Command Ref: Redundant Interface
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 

Author Closing Comment

by:chipsch
ID: 36716498
I actually just found that yesterday but thanks for tracking that down anyways. Only unfortunate part is that it is only supported on the 5510 and above. We also have some 5505's that will have to be worked out.
0
 
LVL 7

Expert Comment

by:Ironmannen
ID: 36719882
Thank you for the points, but I would be glad if you changed it to a split since jmeggers mentioned redundant interfaces as a solution...
and of course you are right with the problem of using 5505 in a corporate environment since they are mainly for SOHOs with their limited features
Cheers!
0
 

Author Comment

by:chipsch
ID: 36814322
Just saw that and thanks for pointing that out about Jmeggers. Is there any way a mod can adjust that or reopen this question so I can adjust it?
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Radius ASA Authentication Failed 4 72
using BGP Attributes 2 87
RV042 site to site vpn can ping but not access server via rdp 6 28
VLANs and isolation / private networks 3 38
Introduction This article explores the design of a cache system that can improve the performance of a web site or web application.  The assumption is that the web site has many more “read” operations than “write” operations (this is commonly the ca…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question