High Availability VWire

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

High Availability VWire

L2 Linker

I am setting up a HA pair of 5060s in vwire mode between two Cisco ASA's and the internal switch. the ASAs are set up has HA.

What is the best way to set up the 5060s in HA to ensure they notice when the ASA fails. I do not want a scenario where the ASA fails but the Palo does not. Then the secondary ASA will be active forwarding traffic to the secondary passive PA that will drop all packets.

Is A/A HA the preferred method or using link and path monitoring on the PA?

1 accepted solution

Accepted Solutions

Correct, you need a unique address for each of the ASA nodes to determine it is not available.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

View solution in original post

3 REPLIES 3

L7 Applicator

If you setup the pair as A/A then you really don't need to do anything else.  Whatever happens on the ASA a valid path will exist.  The disadvantage here is that your HA3 link will need to be sized to accommodate double your max traffic.  Sessions will be owned by the primary node and when failover occurs the traffic will start coming in and out the secondary path.  But session inspection will happen on the primary so the traffic goes over the the primary inspected and returned to the secondary for egress.  You will need to be sure you won't max out the link.

If you use A/P then link and path monitoring should be able to detect the lost of your primary path and trigger the failover.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Okay, sounds like A/P will be the answer.

I know how to set up link monitor. For Path monitoring I would have to ping an IP unique to each firewall correct?

Correct, you need a unique address for each of the ASA nodes to determine it is not available.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 1 accepted solution
  • 3261 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!