04-20-2012 06:59 AM - edited 03-07-2019 06:15 AM
Hi Everyone,
I have a 3560G connected to an ASA FW, both running layer 3 and hosting 6 or so VLANs. The switch is the default gateway for all VLANs (client request) and therefore see's all networks as connected. I used route maps to push the traffic from the switch to the FW so that it got firewalled before being delivered, but I cannot use one of the commands for failover should the FW fail (I wanted to route locally should the FW fail).
So, my question is this. If I placed all VLANs in their own vrf, NETA would not longer see NETB as a connected network and would follow the route to the FW's NETA interface. I could then inject the connecteds into each vrf but adjust theirf metric so that they are less preferable than the route to the FW. Should the FW route die, the next route would become active and traffic would route internally to the switch.
Can anyone see a problem with this idea?
Dan
PS - thanks in advance.
Solved! Go to Solution.
04-20-2012 07:26 AM
How are you planning to inject the routes?
To leak routes between VRFs, you use static routing in the 3560 but you must point the gateway to an external device.
Ideally, you can use the FW as the gateway for those static routes but if the FW is down, the failover static routing approach won't work as expected.
04-20-2012 07:26 AM
How are you planning to inject the routes?
To leak routes between VRFs, you use static routing in the 3560 but you must point the gateway to an external device.
Ideally, you can use the FW as the gateway for those static routes but if the FW is down, the failover static routing approach won't work as expected.
04-20-2012 07:39 AM
thanks Edison.
Im trying to find a workaround for my previous question, but the route map statement isnt supported on 3560G. Any ideas on how I could get around this?
Dan
04-20-2012 07:45 AM
Implementing redundancy at the FWs and only use the switches for Layer2?
04-20-2012 07:50 AM
we only have a single FW and a single switch, unfortunately.
Dan
04-20-2012 07:52 AM
No way around it...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide