Solved

asa failover

Posted on 2015-01-09
4
174 Views
Last Modified: 2015-01-09
I need to do an asa failover, I have attached a picture for identification. Will I be able to do the failover in this situation? I have different IP on each side. The link in the middle between the firewalls will obviously match. Uusally when you do the failover, the interfaces IP’s match, are on the same network. If I can’t do that, are there any other option for me to have an asa failover in this situation?
Untitled.png
0
Comment
Question by:Shark Attack
  • 2
  • 2
4 Comments
 
LVL 3

Author Comment

by:Shark Attack
ID: 40541351
Also, I have two different ISP connections as shown in the picture
0
 
LVL 28

Assisted Solution

by:Jan Springer
Jan Springer earned 500 total points
ID: 40541368
You may be able to do IP SLA on the ASAs for the outside interfaces and VRRP on the inside interfaces (I have not done VRRP on the ASAs.).
0
 
LVL 3

Author Comment

by:Shark Attack
ID: 40541389
is there a reason why I can't do vrrp inside and out or ip sla on inside and outside?
0
 
LVL 28

Accepted Solution

by:
Jan Springer earned 500 total points
ID: 40541393
You cannot do VRRP on the outside interface because they are different subnets.

You might be able to do IP SLA on the inside interfaces but the best thing would be to put IP SLA on a layer 3 switch to select the default route depending upon the SLA configuration.
0

Featured Post

Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question