Cisco Firewall :: ASA 5510 Redundant Interfaces With Stack Switches

Jun 10, 2013

we have two ASA 5510 connected in failover, and a pair of cisco 2960s switch connected in stack. Currently one interface of primary ASA is terminated on switch1 and a interface from standby is connected to switch2 as Inside, and switch1 and switch2 are in stack. for redundancy purpose i want to use multiple interfaces of ASA for inside , so first i thought to use etherchannel , but it has a limitation that , it cannot be terminated on stack switch(as per cisco document [URL]
 
So my question is :
 
1. can we use redundant interface feature where  2 physical interfaces combined to a redundant interface (eg interface redundant 1) for inside redundancy purpose.

2. Can these ports from primary/standby ASA terminated on stack switches (2960s), will this work (if the switch with active port goes down, will the other port take over in the redundant interface with the other switch).

View 1 Replies


ADVERTISEMENT

Cisco Firewall :: Redundant Interfaces In ASA 8.0?

Aug 3, 2009

In ASA 8.0,I have following queries related to redundant interfaces
 
a)While configuring redundant interface can the redundant interface again be divided into logical interface like red1.1 , red1.2 ?

b)Is Redundant interface supported in the Multiple context mode

View 4 Replies View Related

Cisco Firewall :: Redundant Inside Interfaces On ASA 5505

Mar 6, 2011

My customer is running an ASA5505 with 8.3 code.
 
The have a somewhat flaky proxy between their inside LAN and the firewall.  I'd like to have a configuration as follows:
 
 LAN   > Proxy > VLAN 1 (eth0/2) on ASA
 
and
 
LAN > VLAN 1 (eth0/3) on ASA
 
So that in the event of Proxy failure (let's just say it loses power) the eth0/3 interface will kick in.
 
This appears to be easily configured according to the documentation:
 
"The following example creates two redundant interfaces:
 
hostname(config)# interface redundant 1
hostname(config-if)# member-interface gigabitethernet 0/0
hostname(config-if)# member-interface gigabitethernet 0/1
hostname(config-if)# interface redundant 2
hostname(config-if)# member-interface gigabitethernet 0/2
hostname(config-if)# member-interface gigabitethernet 0/3"
 
But these commands don't seem to be available on a 5505.

View 7 Replies View Related

Cisco WAN :: 5510 Simple Network Architecture For Redundant Switches And Firewalls?

Oct 17, 2012

We'll be building a small remote site that will use two Windows 2008 servers.  We would like redundancy in firewalls, IPS's and switches.   Is it better to buy stand-alone ASA 5510s (with embedded IPS's) and 2960s, or is it a better option to buy a  Cat 6000 with FW modules.  We'll have several internet IP addresses available. 

View 2 Replies View Related

Cisco Firewall :: ASA 5510 Redundant Interface Configuration

Aug 14, 2012

I have configured redundant interface on ASA 5510
 
interface Redundant1
description *** INSIDES NETWORK ***
member-interface Ethernet0/1 (This is a 1000Mbps Port)
member-interface Ethernet0/2 (This one is 100Mbps)
no nameif
no security-level
no ip address
[code].... 

Then... i issue following command and its OK!
 
ASA5510# show interface redundant 1 detail
Interface Redundant1 "", is up, line protocol is up
Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
[code]...
 
It's transfer correctly then i no shut and back to normal Primary core switch Gi0/30 Interface again, BUT  redundant interface no revert back. I issued this command again BW remain 100Mbps.

ASA5510# show interface redundant 1 detail
Interface Redundant1 "", is up, line protocol is up
Hardware is i82546GB rev03, BW 100 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
[ code]....
 
I did manually shut down and no shut the secondary core switch interface Gi0/30 Its changed correctly to 1000Mbps .

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - IP Sec VPN On Sub-interfaces

Jun 20, 2012

Can  ASA sub-interfaces run separate IP Sec VPN tunnels eg
 
There are 02 sub-interfaces of 01 physical interface of Cisco ASA5510 [ASA Version 8.2(5)] and I need to run 01 IP Sec VPN tunnel on each of these

View 1 Replies View Related

Cisco Security :: ASA 5520 And Redundant Interfaces Design

Apr 17, 2011

We have two multilayer switches and only one ASA 5520. I'd like to connect ASA in the way described on the picture: each redundant interface includes two physical ones, which are connected to different switches

My question is what kind of link it is necessary to have between switches to make this idea work? I'd have subinterfaces like Re1.100, Re2.200 and so on for my traffic.
 
I understand that correct design approach is to have two redundant firewalls with failover but we cannot purchase the second one yet.

View 1 Replies View Related

Cisco Firewall :: Communication Between Interfaces Of ASA 5510?

Mar 12, 2011

I configured ASA 5510 ...
 
Totally it had 5 ports..
 
How to provide communication between two different interfaces which had configured as same security level?
 
How many trunks will support ASA 5510 with base-license?
 
How to configure trunk to an interface with different VLNs( Router on a stick).

View 6 Replies View Related

Cisco Firewall :: ASA 5510 With Two Outside Interfaces Which Is In Separate ISPs

Jan 5, 2013

I have ASA5510 with PLUSE License.I have 2 Inside interfaces as STAFF and MAIL and two Outside interface OUT_STAFF and OUT_MAIL which is in separate ISP's.now i want to nat STAFF to OUT_STAFF and MAIL to OUT_MAILbecause I'm having two default routes it gets impossible to do.

View 1 Replies View Related

Cisco Firewall :: ASA 5510 Communication Between Two Internal Interfaces

Jun 11, 2013

I've been following most of the comments in regarding how to allow communication between two internal networks on a ASA5510 8.2.5 But I am still a little confused about to how to set my firewall. I made chages to it and still do not have the desired results.
 
I need to allow comunication between Interface 0/1 and Interface 0/2. See configuration file with fake or dummy ip address below.
 
ASA Version 8.2(5)
!
hostname ciscoasa
domain-name lxx.com

[Code].....

View 1 Replies View Related

Cisco Firewall :: ASA 5510 And Having Two Outside Interfaces For Voice And Data

Feb 13, 2012

I have a question regarding firewall configurations. Is it possible to have two interfaces ( for two internet service providers) one for voice and one for data. Can I have two Outside Interfaces that one will apply to a pppoe client group and the other will apply to a static IP? Is this possible and if so What would be the steps on applying this connection? Also to note I have a point to point connection already established for the pppoe. I also have another point to point connection for data, but however I do not know how to apply this to the firewall.

View 3 Replies View Related

Cisco Firewall :: ASA 5510 / Provide Communication Between Two Different Interfaces

Mar 12, 2011

Is it possible to provide communication between two different interfaces which had configured as different security level in ASA 5510?

View 3 Replies View Related

Cisco Firewall :: Communication Between 2 Inside Interfaces On ASA 5510

Oct 23, 2011

I have a Cisco ASA 5510 configured to access the internet, with an:

inside interface (ethernet 0/1) 130.130.0.254 and outside interface (ethernet 0/0) x.x.x.x
 
I have now configured another inside interface (ethernet0/2) on ASA with the IP 172.16.0.254 and I have connected it directly to another switch with a management IP 172.16.0.5.
 
The problem is that the two inside interfaces (130.130.0.254 &172.16.0.254) cannot communicate with each other thus the e0/2 172.16.0.254 interface cannot access the internet.

View 5 Replies View Related

Cisco Firewall :: ASA 5510 - 2 Internet Interfaces Without Traffic

Jan 15, 2013

I need to route to sub nets form 2 different ASA interfaces. The ASA also has an outside interface works like gateway for internet access. Here is my configuration:

ASA Version 8.2(1)
host name ICE3
names
interface Ethernet0/0
name if outside
security-level 0
ip address 201.199.xxx.xx 255.255.255.248
[Code]....

View 9 Replies View Related

Cisco Firewall :: 5510 ASA Cannot Create Sub Interfaces For Intervlan Routing

Apr 8, 2013

I am trying to setup intervlan routing with a Cisco ASA 5510 and two 2960-S switches. The 5510 currently is using ASA Version 7.0(2) and has a base license. I tried to create a sub interface today based on some info I found regarding the routing piece and it didn't recognize the command. I'm thinking I may need to update the IOS code or the license on the firewall. I know the syntax was correct because I looked it up and found it in a Cisco document.

View 15 Replies View Related

Cisco Firewall :: 5510 - Get Internet Connectivity On ASA Inside Interfaces?

Dec 30, 2012

I have a Cisco ASA 5510 with 3 inside interfaces each connected to a 3750X switch port in a vlan. Outside interface is connected to external router with 209.155.x.x public IP. Static route exists for outbound traffic on outside interface.
 
3750X is configured for inter-vlan routing. VLANs 10, 20, and 30 have 172.16.x.1 IP address with static routes pointing to the each of the ASA inside interfaces - 172.16.x.254. Connected hosts are configured with gateways pointing to the appropriate vlan interface IP - 172.16.x.1.
 
Inter-vlan routing appears to be working - I can ping back and forth between hosts on different vlans, and I can ping each vlan IP.I can also ping each ASA inside interface from a host in the appropriate vlan, but I cannot ping internet sites (4.2.2.2 or 8.8.8.8) from hosts on the inside interfaces.
 
I can ping 4.2.2.2 from the ASA CLI. I can ping internal hosts on vlans 10,20,30 from the ASA CLI. But, no luck with pinging from inside host to internet hosts

View 12 Replies View Related

Cisco Firewall :: Unable To Create VLAN Interfaces In ASA 5510

Nov 13, 2011

Unable to create VLAN interfaces in ASA 5510

View 1 Replies View Related

Cisco Firewall :: 5510 EtherChannel Connected To 3740 Stack

Feb 13, 2013

I have a single 5510 ASA and a paired of 3750 Stacked Switches. I was trying to create an Ether channel on the ASA and connected to the SW Stack port channel to support different VLANs sub interfaced at the ASA.  am confused with the following statement from doc. [URL].
 
Section Guidelines and Limitations :

"The ASA does not support connecting an  Ether Channel to a switch stack. If the ASA Ether Channel is connected  cross stack, and if the Master switch is powered down, then the  Ether Channel connected to the remaining switch will not come up. 
 
What "If the ASA Ether Channel is connected  cross stack"? or better. Is it possible to use the ASA 8.4 Port-Channel to connect it to the 3750 ether channel stack?

View 8 Replies View Related

Cisco Switching/Routing :: Add Another Fiber Redundant Link Between 6509 And 2960 Stack?

Jan 6, 2012

below is the current config of link that is already up. I need to add another fiber redundant link between 6509 and 2960 stack. How to work on config Spanning side by not taking 6509 down after the change. 6509 is in distribution.
 
---------------X-ALPHA-IDF-1FORMS-2960S-0# (SIDE)
!interface GigabitEthernet1/0/52description X-ALPHA-F-6509-0 uplinkswitchport trunk native vlan 18switchport mode trunksrr-queue bandwidth share 1 50 30 19priority-queue out mls qos trust dscpmacro description cisco-routerauto qos trust spanning-tree portfast disablespanning-tree guard loopip dhcp snooping trust!
 
-----------------X-ALPHA-F-6509-0# (SIDE)
!interface GigabitEthernet3/10description 1st floor POC2 Forms IDFswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 18switchport mode trunkno ip addressmls qos trust dscpspanning-tree guard loop!

View 1 Replies View Related

Cisco Switching/Routing :: Use Both Interfaces On 2921 To Connect To 3750 Stack Switch 1 And 2

Nov 9, 2012

I have a Cisco 2921 and a 3750 stack. I want to use both interfaces on the 2921 to connect to the 3750 stack switch 1 and 2. Is this possible using same ip subnet?

View 2 Replies View Related

Cisco Switches :: Does SG500X Support Redundant Power Supply

Jun 1, 2013

Does SG500X support the following
 
redundant Power Supply?PIM sparse mode (PIM-SM), PIM dense mode (PIM-DM), and PIM sparse-dense mode?Layer 4 prioritization: enables prioritization based on TCP/UDP port numbersUni-Directional Link Detection (UDLD) — monitors a link between two switches and blocks the ports on both ends of the link if the link goes down at any point between the two devices 

View 2 Replies View Related

Cisco Switches :: SGE2010 Can Use 4 SFP Ports And Stack Of Two Switches At Same Time

Feb 15, 2012

I looking to buy SGE 2010 swith, but I have some question:

1. Can I use 4 SFP ports and stack of two switches at the same time.
2. Is it possible to use for stacking  ports other than 24, 48?
3. What is maximum possible number of ports  to use for stacking (can I get more than 1Gb thruput).

View 0 Replies View Related

Cisco Switching/Routing :: 3750 V2 / Fully Redundant Switches Meaning?

Jun 2, 2013

let me know the exact meaning of attach ( yellow marked one)? the contractor was saying "it doesn't mean two switches as there is a built in redundancy in Cisco switch)"I don't think he is correct as I never heard about built in redundancy in Cisco Router/switchAny comment as this will affect the numbers from 55 (3750 v2) to 110....

View 41 Replies View Related

Cisco Switches :: SG300 Correct Configuration For Redundant Link Between Two Switch

Mar 9, 2012

I have two switch SG300-10 that need to be interconnect togheter with a simple redundant "cable fail safe" configuration.My idea is use the two uplink copper port of the first switch, connected to the two uplink copper port of the second switch.

How to create a working setup configuration? The first setup that i need, is with only one VLAN1 for all ports,
 
The second setup is with the VLAN1 assigned to the ports 1-2-3-4 of all the two switch, (linked togheter by uplink ports)
and the VLAN2 assigned to the ports 5-6-7-8 always linked togheter with the same uplink ports.
 
Is possible use the two uplink port at the same time, as cable fail safe? or use a uplink port 1 for the first group and the second uplink port for second group?
 
I need to use this configuration for audio cobranet transport, and i need to test the correct configuration for the primary and secondary audio stream, if can work togheter on the same VLAN or i need to separate the two stream, from start to the end.

View 1 Replies View Related

Cisco Firewall :: 5550 Firewall Set Up For Redundant Purpose

Mar 3, 2011

i two 5550 firewall set up for redundance purpose . in failover we define two different ip add one for primary and one for secondary .interface Ethernet0/0 nameif outside security-level 0 ip address xxxx.0.0.0.1 255.255.255.0 standby xxxx.0.0.2!interface Ethernet1/0 nameif inside security-level 100 ip address 10.0.0.12 255.255.255.0 standby 10.0.0.11.default gateway for host will be 10.0.0.12 (primary fw address) however in case of failover , the secondary fw will be up with ip address that was assigned for primary .in this case the secondary ip add 10.0.0.11 is actually nerver used? similarly do i need to have two public ip address for outside (one for primary and one for secondary )   ? or in case if primary fails the secondary comes onlie and take the ip of primary fw . hence i only need to purchase just one ip address.

View 6 Replies View Related

Cisco Switching/Routing :: 4900M / 2960 - Two L3 Switches As Redundant / Mated Pair?

Nov 6, 2012

There are two Cisco 4900M L3 switches and two Cisco 2960 L2 switches. I need to configure the two L3 switches to operate as a redundant pair, as the servers connecting to them are connecting using bonded interfaces, which can only have one default gateway. So these two L3 switches need to have the same Vlan interface 1, 2 and 3 IP's set onto them.How are the two L3 switches made aware of each other? via a normal trunk? Is there some special configration for configuring a mated/redundant pair of switches? or are they both just configured as though they were the same switch, but linked?

View 14 Replies View Related

Cisco Switching/Routing :: 3560 - Portable Redundant Power System For Catalyst Switches?

May 10, 2012

Does a portable RPS device either from Cisco or another manufacturer exists, that would allow you to move primary power for a switch without causing an outage? I realize that for the Catalyst 3560 for example, you can get an RPS 2300 or 675, but my understanding is that these are made for a more permanent installation, not to mention rather costly.
 
It looks like the RPS 675 is rather inexpensive after all, especially in the secondary market, but still rather large for toting around.

View 1 Replies View Related

Cisco :: ASA 5510 Ping Between Inside Interfaces

May 4, 2012

I have two inside interfaces (both security level 100) inside and inside110. Inside is 192.168.105.3/24 and inside110 is 192.168.110.3/24. I have a PC on the 192.168.105.0/24 network. I cannot ping the 192.168.110.3 IP of interface inside110.

View 2 Replies View Related

Cisco WAN :: ASA 5510 ASDM 6.1 - Getting Multiple WAN Interfaces?

Aug 20, 2012

I am trying to enable a second WAN interface on our ASA.the end goal is to move all internet traffic to the new connection, but first i want to test it working.I have setup my computer as an object in the ASDM and the interface is configured correctly (same settings on a different router and that was working)I setup a route with a lower metric ( 1 lower than the default route which routes everything through current main internet interface) to route traffic from my computer out through the new interface but i am still connected on the old interface.I duplicated some of th NAT rules  (but i would have thought if these werent working then i would have no internet connection anyway)

View 5 Replies View Related

Cisco VPN :: Remote User VPN Across Interfaces 5510

May 5, 2013

I have a client that wants to segment their wireless network behind their ASA.  We currently have a normal setup, 5510, 2 interfaces, outside, inside.  On the inside network there are Cisco Wireless APs that allow for internal access to the network.  We want to move the APs to a new interface on the ASA and only allow traffic bettwen this new "Wireless" network and the internal network by using remote user VPN.  So my question is, can you use remote user VPN from the new Wireless network to the inside network?? 

View 1 Replies View Related

Cisco WAN :: Forcing Traffic Through Specific Interfaces ASA 5510

Mar 6, 2012

How to force traffic back out the same interface from whence it entered.  Review the following topology.
 
Internet ---> ASA 5510 ---> Static IP1 ---> F3.1 ---> 1811 F0
                             |-------> Static IP2 ---> F3.2 ---> 1811 F5 ---> VLAN Int
 
ASA F3.1        10.1.254.9/30
ASA F3.2        10.1.254.13/30
1811 F0          10.1.254.10/30
1811 F5          10.254.1.14/30
 
When pinging the public IP of ASA F3.2 from the internet a reply is never received because the default route on the 1811 points to ASA F3.1.
 
How do I get the replies from the 1811 to go back out the same interface from whence it entered ? I am sure the answer is policy-based routing, but not sure how to write the config.

View 1 Replies View Related

Cisco VPN :: 5510 - Site-to-site IPsec VPN / ASA To IOS And Redundant ISPs?

Oct 3, 2012

Site A has an ASA 5510 and a single internet connection.Site B has two internet connections (primary and backup). If Site B also has an ASA, I can configure Site A's ASA to deal with a failover at Site B (set peer 1.1.1.1 2.2.2.2). Does this work if Site B has an IOS router instead of an ASA? In other words will "set peer 1.1.1.1 2.2.2.2" on the ASA work when it's talking to IOS on the other end?

View 15 Replies View Related

Cisco Security :: ASA 5510 / Routing Http Flow On Two Different Interfaces?

Jun 21, 2012

I use 3 interfaces on an ASA 5510. First interface is Lan, Second interface is Outside, Third interface is ADSL The Outside interface is used for VPN L2L and smtp traffic. (Leased line on router managed by ISP)The Adsl interface is used for Http traffic. (Adsl Cisco router) I use this configuration found on another forum subjet for routing.route outside 0.0.0.0 0.0.0.0 x.x.x.x 1route adsl 0.0.0.0 0.0.0.0  y.y.y.y 2 nat (inside) 1 0 0global (outside) 1 interfaceglobal (Adsl) 1 interface static (Adsl,inside) tcp 0.0.0.0 www 0.0.0.0 www netmask 0.0.0.0 The problem is now I have an www intranet server on the VPN remote site. How i can exempt the http traffic to the intranet server routed through Adsl interface?

View 7 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved