Solved

ASA Firewall redundant vs etherchannel

Posted on 2014-04-07
6
1,333 Views
Last Modified: 2014-04-08
Hi,

I am setting up a pair of 5512-X outside network with 2x Cisco 2960C switches connecting to our service provider through an access port on each of the switch.

Since Etherchannel accross the 2960C's is not an option, would you:

1) Etherchannel from Firewall A to 2960C A and Etherchannel from Firewall B to 2960C B (with trunk between the 2960C's)

2) Each firewall have uplink to each 2960C and use redundant interfaces

Please let me know why you would favor any of the options.


Thanks.
0
Comment
Question by:random0
  • 3
  • 3
6 Comments
 
LVL 5

Accepted Solution

by:
Martin Tarlink earned 500 total points
ID: 39984444
Option 2) seems more reasonable because you can set up redundancy
Could you specify which model of2960C you have?
0
 

Author Comment

by:random0
ID: 39984614
They are the 8x100Mb + 2 Gb model.

2960C-8TC-L
0
 
LVL 5

Expert Comment

by:Martin Tarlink
ID: 39984866
I forgot also to ask:

Could you provide more information about your topology?
Do you have one or two ISP modems?
Do you want to use ASA in active/active or active/standby failover.
Do you plan to use multicontext on ASA?
Do you plan to use static NAT to IPS (how many devices)?
Do you plan to use IP inter vlan routing inside that network, VPN.

Also what IOS level you have on your ASA?
Your compact switches supports only LAN Base features so you have to aware of what you can and what you can't do with them.

With Cisco everything I asked could be set up different ways depend what you want to accomplish.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 

Author Comment

by:random0
ID: 39984899
- The 2960C switches are only for the up links to provider
- Provider supplies 2 access port to a vlan with 2 routers with hsrp running
- Active/Passive failover
- Single context
- No IPS module
- inside network will be served with L3 switches, the compact switches are only the "outside" switches

Now that i think about it, the redudant interfaces make more sense since they will cover more failure scenarios without triggering a firewall failover.
0
 
LVL 5

Expert Comment

by:Martin Tarlink
ID: 39985038
I am not sure now if you need those two switches , why not to plug ISP -Vlan ports to ASA directly, and configure IP address on ASA to match ISP routers.

Not sure how ASA will receive IP - statically / dynamically from ISP
Does your ISP provide your gateway IP address?

If you will have L3 inside your network with IP Service you can set PBR and SLA tracking and if one connection to your ISP will go down inside router will switch the routing patch. The same will be if one of your ASA will go down.
It could be much easier if your ISP can provide 2x "no switchport"  interfaces.

I do not see how you will program those 2960C-8TC-L LAN Base switches. For me those are Layer 2 edge devices.

You have mentioned that your ISP runs HSRP (which is a little limited) means ISP have Cisco router behind. If you can convince your ISP  to run GLBP will be able to run active/active :)
0
 

Author Comment

by:random0
ID: 39985656
I just need layer 2 connectivity to the ISP, they provide me with a static range, but we are beyond the scope of my original question.

The switches are there to connect other devices on that static range.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Hi there, This article summarizes what you need if you are going to set up your home or small business Network Attached Storage (NAS) to be accessible from the internet. Of course there are configuration differences based on your NAS or router ma…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now