Solved

PIX to ASA 9.1

Posted on 2014-10-16
7
83 Views
Last Modified: 2015-03-13
I am about to deploy a new ASA into a network. We will be replacing a rather old PIX as a result.

We will be leaving the PIX in place for a time period as a precautionary backup.  If the ASA doesn't work (It will be configured the almost the same as the PIX), can I plug the PIX back into the network as an added measure of precaution?

i'm worried that the switches will see the PIX's IP address however the MAC address will be different.  Will this matter?
0
Comment
Question by:beckredder
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
7 Comments
 
LVL 12

Expert Comment

by:DarinTCH
ID: 40385213
not the best scenario
like a car with 2 steering wheels

there are a few vendors boxes designed to work in harmony with another device like the paloAlto firewalls which
work in a VWire mode - kinda inline if you will
they use this for POC - Proof of concept and then a staged migration

but PIX and ASA i wouldn't
besides you PIX is rather old - ASA has been out for a long while - and should accomplish everything
the PIX does and much more

now that doesn't mean it worthless - maybe could be used in other scenario / location
but running both in a pseudo concurrent situation is asking for extra trouble
0
 

Author Comment

by:beckredder
ID: 40385272
Thanks very much for the feedback.
0
 

Author Comment

by:beckredder
ID: 40386398
Darin, another question in regards to this scenario.

We need to setup 4 vlans in the network, is it advisable to do this at the router or will I have to do it at each switch.

regards,
0
Get MySQL database support online, now!

At Percona’s web store you can order your MySQL database support needs in minutes. No hassles, no fuss, just pick and click. Pay online with a credit card.

 

Author Comment

by:beckredder
ID: 40386399
or both switch and router...
0
 
LVL 12

Accepted Solution

by:
DarinTCH earned 500 total points
ID: 40386654
depends on which layer u want to communicate layer 2 or layer 3
L2 would be MAC addresses and @ switch
most folks are more comfortable with IP addresses
so L3 is IP @ router

still need to tuen vlan tagging on @ switch if you plan on having all 4 vlans in each switch
802.1q tagging ....will assist with traffic processing throughout the vlans
0
 

Author Comment

by:beckredder
ID: 40394357
Darin, I will be attaching two Cisco 3850s to the ASA 5545 Firewall device.  I would like to add some measure of failover for the 3850's.  Should this stack be redundant? Or should the ports (24*2) be shared?

If I do connect the switch to the two redundant links (1 to each), can we be assured that there are no loops?
0
 

Author Closing Comment

by:beckredder
ID: 40663223
Thanks!
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question