cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
375
Views
0
Helpful
2
Replies

Transparent mode and failover.

pauloroque
Level 1
Level 1

Does an ASA in both transparent mode and standby state pass any type of traffic?

Paulo Roque

Network Engineer

2 Replies 2

Not applicable

Transparent firewall mode allows only two interfaces to pass through traffic; however, on the ASA adaptive security appliance, you can use the dedicated management interface (either the physical interface or a subinterface) as a third interface for management traffic. The mode is not configurable in this case and must always be management-only

mvandorp
Level 1
Level 1

In transparent mode, all allowed traffic is passed, but only IP-traffic can be inspected. Normally BPDUs are blocked, but you want them through if using STP.

In transparent failover mode, you definitely want STP, to eliminate problems when both FWs become active (should never happen, but...).

In standby mode, the FW does not pass any traffic.

There is a failover link between active and standby FW, to carry FW status info. If you do stateful failover, the state-info is transferred too (on it's own VLAN). This is management traffic, no user data!

I don't know about ASA, but an FWSM allows up to 8 BVI-groups per context. An inside VLAN is connected to an outside VLAN by the transparent FW (this is called a BVI-group). Each BVI-group is completely isolated from each other. You need a router to get traffic between the BVI groups.

Thr management interface is just for that. It also can carry traffic for AAA (eg. a connection to the radius server).

HTH,

Marcel

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card