I have configure active/active failover on two boxes.
but, It looks two active/standy add togother. (subnet 1 traffic go to first asa5520 and subnet 2 traffic go to second asa5520).
If possible I can setup one subnet share the load on both asa5520s? If so, how can I do it?
Any comments will be apprecaited
Thanks in advance
ASA5520 datasheet states throughput upto 450Mbps and for vpn its 225Mbps, so when you are designing the solution you should consider the existing network setup and also the volume of growth for future.
In your case its a multi context setup, so it won't support VPN's ,dynamic routing, so you have need not worry of using these features in future.
However, sometimes you may experience high traffic/ firewall resource utilisations due to some malwares or performing VA scans via firewall
To avoid such situations,
Configure the firewall to perform anti-spoofing, prevent dos attacks by limiting/ controlling simultaneous connections/sessions.
Here is a Cisco link for preventing Network attacks.