I see a lot of ASA designs and they are typically flanked with switches. One of the reasons for this is that the failover requirements typically dictate that the devices to be layer 2 adjacent in each security zone. There is obviously the requirement to be L3 directly connected to their next hop. The result of this requirement that an ASA can’t typically be directly connected directly to an L3 only device and it is often the case that a switch is sandwiched between the FW and the next L3 device.
This article is meant to outline a possible work around with IOS and IOS-XE based routers to provide the L2 two adjacency using inherit L2 features. Readers may use these sample configurations to build out there own labs and more fully validate the applicability the their environment.
TL;DR–BDI and BVI allow ASA A/S to function properly in my testing.
Below is the topology that used for validating this. In a real world scenario it is less likely that routers would be the connection point on all interfaces. The reason I positioned them here is to demonstrate both IOS and IOS-XE techniques in the same lab.
The writing masses in addition to professional media generate tons of articles each week. What’s the best way to keep up? My strategy is multi-pronged.
Filter quickly and mercilessly. Read only the most interesting articles.
Keeping up with technology is a big part of my business. Therefore, I subscribe to feeds about emerging tech from news organizations, independent tech writers, and technology vendors. From these sources, I monitor trends and hype, picking out what strikes me as useful or at least thought-provoking for IT practitioners. Articles that match this criteria inspire articles of my own as well as podcast scripts, and spawn research projects. My overarching goal is Continue reading
The post Worth Reading: Lights at war appeared first on 'net work.
The company is suffering from supply threats and lags in 4G sales.
The partnership marks Ruckus’ first step towards IoT.
20th Century Fox envisions storing movies at the network edge for immediate download.
The money could help in a crowded CASB market.
T-Mobile accelerates IoT; Viptela partners with Inbox Business to deploy SD-WAN in Pakistan.