Link to home
Start Free TrialLog in
Avatar of David Mundt
David MundtFlag for United States of America

asked on

Cisco ASA 5516x failover network diagram

I’m preparing to add a second ASA 5516X to be a failover and am looking for a simple network diagram for 2 ASAs so I can understand how it needs to be connected.
ASKER CERTIFIED SOLUTION
Avatar of David McMorris
David McMorris
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of David Mundt

ASKER

Perfect! This is precisely what I thought!

Thanks,
David
I'm a little confused about some things. In particular what will happen when both ASAs are receiving traffic from the same public range. I know if they were not set in failover (active/standby) this would cause all sorts of issues. As for internal config such as DHCP I guess I'd need to define 2 gateway addresses in the event of a failover?

IP Ranges are examples
Public IP Range 10.0.0.1/29
ASA1 Outside Eth00 10.0.0.2
ASA1 Inside Eth01 192.168.1.1/24
ASA1 (Active) Eth02 <-----> ASA2 (standby) Eth02

ASA2 Outside Eth00 10.0.0.3  
ASA2 Inside Eth01 192.168.1.2/24
ASA2 (standby) Eth02 <-----> ASA1 (active) Eth02
Hi,

You don't need to do any configuration on the standby ASA. If you do the failover config correctly on both firewalls, synchronisation of the config from the active firewall will occur from active to secondary.

Thanks,

David
Thank you David... I had a suspicion but wanted confirmation!!!