Solved

PIX to ASA 9.1

Posted on 2014-10-16
7
75 Views
Last Modified: 2015-03-13
I am about to deploy a new ASA into a network. We will be replacing a rather old PIX as a result.

We will be leaving the PIX in place for a time period as a precautionary backup.  If the ASA doesn't work (It will be configured the almost the same as the PIX), can I plug the PIX back into the network as an added measure of precaution?

i'm worried that the switches will see the PIX's IP address however the MAC address will be different.  Will this matter?
0
Comment
Question by:beckredder
  • 5
  • 2
7 Comments
 
LVL 12

Expert Comment

by:DarinTCH
ID: 40385213
not the best scenario
like a car with 2 steering wheels

there are a few vendors boxes designed to work in harmony with another device like the paloAlto firewalls which
work in a VWire mode - kinda inline if you will
they use this for POC - Proof of concept and then a staged migration

but PIX and ASA i wouldn't
besides you PIX is rather old - ASA has been out for a long while - and should accomplish everything
the PIX does and much more

now that doesn't mean it worthless - maybe could be used in other scenario / location
but running both in a pseudo concurrent situation is asking for extra trouble
0
 

Author Comment

by:beckredder
ID: 40385272
Thanks very much for the feedback.
0
 

Author Comment

by:beckredder
ID: 40386398
Darin, another question in regards to this scenario.

We need to setup 4 vlans in the network, is it advisable to do this at the router or will I have to do it at each switch.

regards,
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:beckredder
ID: 40386399
or both switch and router...
0
 
LVL 12

Accepted Solution

by:
DarinTCH earned 500 total points
ID: 40386654
depends on which layer u want to communicate layer 2 or layer 3
L2 would be MAC addresses and @ switch
most folks are more comfortable with IP addresses
so L3 is IP @ router

still need to tuen vlan tagging on @ switch if you plan on having all 4 vlans in each switch
802.1q tagging ....will assist with traffic processing throughout the vlans
0
 

Author Comment

by:beckredder
ID: 40394357
Darin, I will be attaching two Cisco 3850s to the ASA 5545 Firewall device.  I would like to add some measure of failover for the 3850's.  Should this stack be redundant? Or should the ports (24*2) be shared?

If I do connect the switch to the two redundant links (1 to each), can we be assured that there are no loops?
0
 

Author Closing Comment

by:beckredder
ID: 40663223
Thanks!
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

There are times where you would like to have access to information that is only available from a different network. This network could be down the hall, or across country. If each of the network sites have access to the internet, you can create a ne…
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now