David Mundt
asked on
Cisco ASA 5516x failover network diagram
I’m preparing to add a second ASA 5516X to be a failover and am looking for a simple network diagram for 2 ASAs so I can understand how it needs to be connected.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
I'm a little confused about some things. In particular what will happen when both ASAs are receiving traffic from the same public range. I know if they were not set in failover (active/standby) this would cause all sorts of issues. As for internal config such as DHCP I guess I'd need to define 2 gateway addresses in the event of a failover?
IP Ranges are examples
Public IP Range 10.0.0.1/29
ASA1 Outside Eth00 10.0.0.2
ASA1 Inside Eth01 192.168.1.1/24
ASA1 (Active) Eth02 <-----> ASA2 (standby) Eth02
ASA2 Outside Eth00 10.0.0.3
ASA2 Inside Eth01 192.168.1.2/24
ASA2 (standby) Eth02 <-----> ASA1 (active) Eth02
IP Ranges are examples
Public IP Range 10.0.0.1/29
ASA1 Outside Eth00 10.0.0.2
ASA1 Inside Eth01 192.168.1.1/24
ASA1 (Active) Eth02 <-----> ASA2 (standby) Eth02
ASA2 Outside Eth00 10.0.0.3
ASA2 Inside Eth01 192.168.1.2/24
ASA2 (standby) Eth02 <-----> ASA1 (active) Eth02
Hi,
You don't need to do any configuration on the standby ASA. If you do the failover config correctly on both firewalls, synchronisation of the config from the active firewall will occur from active to secondary.
Thanks,
David
You don't need to do any configuration on the standby ASA. If you do the failover config correctly on both firewalls, synchronisation of the config from the active firewall will occur from active to secondary.
Thanks,
David
ASKER
Thank you David... I had a suspicion but wanted confirmation!!!
ASKER
Thanks,
David