Deploy Cisco ASA 55xx in Active / Standby Failover
| |||||||||||||||||||||||||
Problem | |||||||||||||||||||||||||
You want to deploy 2 Cisco ASA 55xx Series firewalls in an Active/Standby failover configuration.
| |||||||||||||||||||||||||
Solution | |||||||||||||||||||||||||
Assumptions.
Hardware on both ASA firewalls is identical.
In this example the firewalls were ASA5510's and all interfaces were being used, so the Management port was used as the "Failover Link" (That needs a security plus licence!).
This Link will use a crossover cable (Only available after version 7.0(2) before that you had to use a switch - I think!).
Also I'm using the same link for LAN Based failover (heartbeat) AND Statefull replication.
IP Addresses
Each interface will need its existing IP address, and an address to use whilst in "Standby". In this example I will use the following,
Outside Interface (Ethernet 0/0) 123.123.123.123 255.255.255.0
Outside Interface STANDBY 123.123.123.124 255.255.255.0 DMZ1 Interface (Ethernet0/1) 192.168.1.1 255.255.255.0 DMZ1 Interface STANDBY 192.168.1.254 255.255.255.0 DMZ2 Interface (Ethernet0/2) 192.168.2.1 255.255.255.0 DMZ2 Interface STANDBY 192.168.2.254 255.255.255.0 Inside Interface (Ethernet 0/3) 172.16.1.1 255.255.255.0 Inside Interface (STANDBY) 172.16.1.254 255.255.255.0 Failover Interface (Management0/0) 172.16.254.254 255.255.255.0 Failover Interface STANDBY 172.16.254.250 255.255.255.0
|
Monday, 14 May 2012
Deploy Cisco ASA 55xx in Active / Standby Failover
Labels:
CISCO ASA
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment