Dual ISP ASA and Dual Failover

Unanswered Question
Feb 22nd, 2008

We have 2 separate sites linked via a 10MB connection with an ISP connection at each site (these ISPs are also or will be BGP peers for each other).

At each site there is 1 ASA firewall with a 10MB link to the alternate sites ASA firewall.

If the firewall on one site is unavailable I would like the 2nd firewall to take over as default route for all the subnets behind them. The heartbeat messages between the ASAs will take place over the 10MB dedicated link between the sites.

I would like to know the best way to set up. Ie... Cluster or Active / Passive Failover?

Furthermore if anyone has set up something similar to this and used a BGP resiliency solution from their ISP provider to do something like this before?

Thanks for your help

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
abinjola Fri, 02/22/2008 - 14:58

how are ASAs connected ?

Lan----ASA2---Router 1---ISP1

Lan----ASA2---Router 2--->ISP2

How is ASA1 and ASA 2 connected ?


This Discussion