I have a n HA pair of ASA and will be implementing an HA pair of PANS between the Core and ASAs. I can send a topology if necessary. Currently have a Cisco 3750 layer 3 connected to two separate Cisco 2960s via a trunk link. The2960s are aslo inter-connected via a trunk link. The ASAs are connected to each 2960 via access port. The original idea was to implement the Palo Altos in A/P but it seems easier to implement A/A. Are there any gotchas for this scenario. I know it is best practice and recommended for Vwire A/A in a layer 3 topology only and to make sure spanning-tree is configured properly for layer 2. From what I have read you should not carry the Vwire vlan across the inter-switch trunk but wold this just be for the trunk between the 2960's or all of the trunk links? I would think the traffic would not pass if the vlan is not allowed between the 3750 and 2960 trunks.
... View more