[fw-wiz] best practices for configuring two ASA5520 with IPS module in Active/Active failover mode



Hello all,

We have 2 Cisco ASA5520 with AIP-SSM-20 that will be replacing two PIX
515s.

We'd like to configure the two ASA in Active/Active failover mode which
requires the use of multiple contexts and 2 failover groups. The
interfaces we'll be using will be inside, outside, dmz1, dmz2, dmz3. I'm
wondering if I should assign interface inside and outside to context1
and dmz1/dmz2/dmz3 to context2, then put context1 on asa1 in failover
group1 and context2 on asa1 in failover group2 (and vice versa on asa2).
Is there a better way to do it? Obviously interface inside and outside
will be heavily used whereas the dmz interfaces will produce less
traffic, so asa1/failover group1 which is configured with interface
inside and outside will be used more heavily then asa2 which passes
traffic only for the three dmzs. Does anybody here have any experience
with setting up the ASA in a similar scenario? If so could you share
your experience with us please? What's the best practice and what are
some questions I should ask myself?

Thanks in advance.



--

Rossella



_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Relevant Pages

  • Re: VPN IP Addressing Problem
    ... to the inside interface of the Router. ... can use the ASA interface for both the PAT and the VPN address, ... Can I just VPN to the public IP that is NATed to the ...
    (comp.dcom.sys.cisco)
  • Re: VPN IP Addressing Problem
    ... to the inside interface of the Router. ... that same subnet is already being used for my mail server (static NAT). ... can use the ASA interface for both the PAT and the VPN address, ... Can I just VPN to the public IP that is NATed to the LAN ...
    (comp.dcom.sys.cisco)
  • Re: VPN IP Addressing Problem
    ... If I took the public IP I am using for PAT and applied it to the ... to the inside interface of the Router. ... can use the ASA interface for both the PAT and the VPN address, ... Can I just VPN to the public IP that is NATed to the LAN ...
    (comp.dcom.sys.cisco)
  • ASA 5505 Outside problem
    ... I have configured a new 5505 ASA with Security Plus licence. ... With show interface I haven't any error. ... 1702 packets output, 224296 bytes, 0 underruns ... minute output rate 0 pkts/sec, ...
    (comp.dcom.sys.cisco)
  • Re: Adding an extra IP net to an external interface
    ... Why do you need an extra set of IP addresses on the interface? ... Is it necessary that the ASA be pingable at the new IP range? ... add appropriate entries to the outside interface ACL ...
    (comp.dcom.sys.cisco)