Re: Default route in switch in a dual-ASA scenario....

From: Bogdan Sass <bogdan.sass_at_catc.ro>
Date: Fri, 15 May 2009 15:59:35 +0300

Cisco Nuts wrote:
> Thanks !!
>
> So the default route in Both switches should point to the physical IP
> of ASA 1 then?
    Yes.
>
> Since HSRP is configured in the switches, I was assuming that both
> switches would point their default route to the HSRP IP NOT the actual
> physical IP of ASA 1 ??
    Once again - this is not HSRP. It is ASA failover, which is different.

> If the ASA 1 box goes down, how will switch #1 start routing out to
> ASA 2 ?
    When the secondary ASA detects that the primary is no longer
reachable, it will start responding to the primary's IP address.

> If the default route pointed out to the HSRP IP, then I see no issue,
> but since right now the default route is pointing out to ASA1 physical
> IP, how would that work?
    See above - when ASA 1 is no longer reachable, ASA 2 will take over
the IP address (just like in HSRP, when the active unit fails, the
standby unit will take over the HSRP IP address).

-- 
Bogdan Sass
CCAI,CCSP,JNCIA-ER,CCIE #22221 (RS)
Information Systems Security Professional
"Curiosity was framed - ignorance killed the cat"
Blogs and organic groups at http://www.ccie.net
Received on Fri May 15 2009 - 15:59:35 ART

This archive was generated by hypermail 2.2.0 : Mon Jun 01 2009 - 07:04:43 ART