Only AAS, 2 inside the kernel switches (HSRP) Best Practice Design

Hello

I design a N/W with following equipment.

1: 2 * carrots (4503)

2: single Firewall ASA 5520

I have following design options;

DRAWING 1:

  1. Basic switches use HSRP
  2. VLANs are active on a (primary) switch at a time
  3. CONNECT THE TWO CŒURS WITH ASA
  • ASA E0 - outside (routers) switch
  • ASA (redundant interface = E1 + E3) R1 - the two nuclei (HSRP)
  • ASA E1 - Core 1 (F3/48) + ASA E3 - Core 2 (F3/48)
  • ASA E2 - switch DMZ

DESIGN 2:

  1. Basic switches use HSRP
  2. VLANs are active on a (primary) switch at a time
  3. CONNECT THE TWO CŒURS FOR LAYER 2 SWITCH (INNER AREA)
  4. CONNECT THE LAYER 2 SWITCH TO ASA E1

The first options looks better avoid me point single failure (Layer 2 of insdie switch).

Unfortunately, I'm short on time and do not currently have access to the LAB.

Please

  1. Share your experience and suggest which option is preferable
  2. Advantages, disadvantages during the failover hsrp, other features, etc.
  3. indicate if there is an alternate option
  4. Precautions

BR,

ABDUL MAJID KHAN

Your "redundant ASA interface" is not really. Only one ASA has no real redundancy. I guess you could make a "inside the 1" and "inside 2", but they would have separate IP addresses and within hosts would not automatically from one to the other. " I would say that the complexity that introduced more than offset the second idea to have a small switch L2 VLAN between your ASA unique within the interface and your L3 core switches.

That's why I prefer the second option. A switch L2 deemed unchanged configuration being done is quite reliable - I regularly fall on them with years of availability. You can also add a quasi redundancy in option 2 by tying together your ASA E1 interfaces and E3 in an etherchannel (requires a Software ASA 8.4 or later version). that option is not possible with option 1 (at least not in the two basic switches) as an Etherchannel are two IOS switches at one end.

Tags: Cisco Security

Similar Questions

  • Is access to the DMZ on VPN best practices?

    Hello

    We have aDMZ which hosts comments wireless society and also installed on the same network of network security cameras. We must be able to access these security cameras remotely (from office) and one way to do that would be to include a network DMZ on your remote access VPN access. I don't know if this is a good/best practices since the same DMZ network also called Wireless on it.

    I think that since the security/DVR cameras is something private, they should be moved inside the network instead of on the DMZ.

    Could you please comment and suggest?

    Thank you.

    Yes! Move the inside security cameras and create another guest lan, do not use the demilitarized zone for the guests!

    DMZ must expose several services outside.

  • Custom object of the quantities Record Field (best practices)

    Hello

    I've been searching but can't seem to find the best practices or recommendations on how many fields to the max may or must be in a single record from custom object. Is there someone out there who could give some information on this? or perhaps point me to some documents or articles on the subject?

    Thank you!

    You can take the class effective Marketing with the custom object class to better understand.  An excerpt from the guide of the student with the limitations thereon:

  • Removes the source of capture-best practices

    What are the best practices for capturing removes the source (10g)? I need to put the data in the data warehouse. Asynchronous CDC can do the job, but should I be aware of? If someone can talk about best practices of implementation of this? Other options?
    Thanks in advance.

    Published by: Rinne Sep 23, 2010 11:05

    do a delete trigger or enable auditing
    concerning

  • How to invoke actionlistener inside the af:switcher element

    Hi guys,.

    I'm working on Jdeveloper 11.1.1.6 and I have this situation: a selectOneChoice component that shows a particular aspect of an element of switching, and inside this facets, there are a few commandButton with Actionlistener. This id code:

    < af:selectOneChoice value = "#{requestScope.panel}" autoSubmit = "true" valuePassThru = "true" > "

    < f: selectItems value = "#{backingBeanScope.Bean.List}" id = "si2" / > "

    < / af:selectOneChoice >


    < af:switcher id = 's2' facetName = "#{requestScope.panel}" >

    < f: facet name = "FACET1" >

    < af:commandButton id = actionListener = "#{backingBeanScope.Bean.Btn_actionListener"cb1"} ' / > "

    < / f: facet >

    < / af:switcher >

    The problem is that the actionlistener the command button does not work. How can I solve this problem?

    Thank you!

    Hello

    There is another problem with your code (next to the realization by dvohra21). Select only one value is saved in a scope of application memory, which means that it is not persisted beyond application. The scope should be at least viewScope.

    Frank

  • is it possible to delete pictures off I phone while only keeping them inside the cloud

    Hi can anyone tell me if you can delete photos from your phone I free up space, but still have them in I cloud, & if so, how?

    Thank you Dr. Beat

    iCloud is supposed to be a device synchronization and not simply used for external storage.  You can use iCloud photo library to "optimize" the storage space on your iPhone if:

    iCloud: use iCloud photo library on your iOS device

    Optimization of the storage on your device

    When iCloud library is turned on, your device can optimize its storage keeping smaller versions of your photos on the device. All your original high-resolution is stored in iCloud photo library and can be downloaded at any time.

    • Go to settings > iCloud > Photos (or settings > Photos & camera), then click on [device] Optimize storage to activate it.

    When your device needs more storage, it automatically replaces certain original high resolution with optimized versions. If you want to replace the optimized with original life-size versions, press download and keep the originals to activate it.

  • Form multipart with fields in the process of disappearance; best practices

    I have a very complex shape with about 500 fields divided into about 25 groups of tabs. Not all fields are applicable, or any tab groups.  There is an integer variable 'type of form' which determines which fields are applicable.   I have the ability to place a special character in the database for a field indicate that it is not applicable.

    The visible fields are overlapping sets, i.e. a, b, c may be visible in a condition all in b, e, f are visible in another.

    It is not enough to turn them off, I want the fields not applicable to disappear and to not leave an empty spot on the Panel where they would be displayed.

    I looked at the STATES, but the complexty of the overlay defines overwhelmed me.  I was worried that everything would be good for a few games, but most have been implemented, I'd get too complex code to debug and maintain.

    The best solution I can think of is to adjust the height to 0 if a field is not applicable.  Since I had subclass the form widgets flex for other reasons anyway, it's not too hard.  It just seems like there should be a better way.

    Can I use Flex 3 or 4.  Any suggestions?

    You must define includeInLayout to false too.

  • Recommendations or best practices around change of the audio data on a network share?

    I have several users editing audio located on the same network share. They are always complaining about the performance.  Is it a best practice to edit audio located on the network?  I see so many issues (latency time, possible corruption, etc.) with that from the computer SCIENCE point of view, but I would like the opinion of those more familiar with the application and its best practices.  Thanks in advance.

    It's crazy! So that any audio to be edited with any degree of speed and security, it must be downloaded to a local computer, edited on that, and then the final result re-recorded on the network.

    You might as well do this anyway - at the time wherever you make a change, you store a local version of the file temp on the editing machine, and it has real save, or save as who turned to the network drive. Also, you would be working on a copy, the original is still available in the case of the vis - is up, and would not be the case if you edit the original files directly on the network, so it is intrinsically safer.

  • How to make transparent cluster keeping only the elements inside the visible cluster?

    Hello

    Can anyone suggest me how to make transparent cluster keeping only the elements inside the cluster visible in the front panel.

    Thanks in advance,

    Vinciane

    As I said, use the space bar for what is paint. This works. Trust me.

    PS You cannot link to pictures stored on your hard drive. We don't see them. You must add them as attachments and then submit the post they get uploaded to the servers of NOR.

  • MuseJSAssert: Error calling the function switch: TypeError: $(...). toBrowserWidth is not a function only on Firefox Cookies are erased and problem not solved.

    Receive error message

    MuseJSAssert: Error calling the function switch: TypeError: $(...). toBrowserWidth is not a function

    only on Firefox

    for the url

    www.tx4you.com/index.html

    Please help

    browsererroroct2014.png

    Clear the cache of Firefox (no cookies). Preferences > advanced > cached Web Content click clean now. FWIW, loading the page just fine for me in Firefox.

  • Network management - only the virtual switch

    I installed latest ESXi 4 Update 1, which is available. I m running Active Directory LAB on several virtual servers Windows 2008 R2 and one of them acts as a router with RRAS role. I m creating 3 different subnets and one of them must be only virtual - no material connection NIC in the interface of ESXi´s it seems that I can't do this, while creating the new switch virtual it forces me to select NIC it becomes a problem, because if I use a virtual switch for Windows 2008 router has the physical NETWORK map It will come to mean that the cable is disconnected. And I need a virtual connection between virtual servers only, that they will be the single subnet between them and communication to physical clients will go through this router´s of Windows 2008 NIC that is not supposed to be physical.

    How can I archive with ESXi?

    You can create a vSwitch without attached Teddy.

    Do not select any NIC, or delete them after the creation of the vSwitch.

    André

  • panic the kernel Linux (CentOS 5.3) VMWare environment only

    I have I try to install CentOS 5.3 in VMWare Server 2.x. The host system running Windows 2000 SP4 with a CPU AMD Athelon XP 1800, 1 G of RAM, and an NVidia FX5200. Whenever I try to install CentOS 5.3 the result is always the same, a panic of the kernel/kernel oops. I have other virtual machines running in the same material without problem, but these virtual machines are running FC4 and earlier versions of RedHat.

    Like many I can diagnose the problem isn't seams to be associated CentOS. I believe that this is true because I tried to install CentOS 5.3 directly in the host system, and I can reach the stage where partitions are created, step I can't achieve when trying to install CentOS 5.3 in my virtual machine in VMWare Server 2.0.

    I tried to increase the RAM memory used by the guest operating system, but the problem persists. I tried to disable acpi (setting the acpi = no as a startup option), made the installation using the text mode, but the same problem, the kernel panic.

    According to the kernel panic information on diagnosing the problem happens in the xor_sse_2 function.

    The call trace shows the following:

    -


    apic_timer_interrupt

    xor_sse_2

    do_xor_speed

    calibrate_xor_block

    sys_init_module

    syscall_call

    Code: Value of Bad EIP

    -


    I upploaded kernel panic message, as it was printed in the VMWare Console.

    I tried to disable all sorts of acceleration in the VM configuration, changed the virtual BusLogic at LSI SCSI controller type, but the same question. I looked for the functions in the call trace service, it seems that calibrate_xor_block is used inside the md driver/module, so it must be a problem with the virtual hardware (disk, CD-ROM, etc.). I changed the virtual CDrom material from IDE to SCSI and now the guest what OS can't find the CD-ROM drive, or the hard drive, but there is also no kernel panic! Y at - it a LSI driver disk that can be used for the virtual SCSI cdrom and the hard drive is accessible?

    Does anyone has any suspicion?

    Thank you

    Mike

    sp3sp3 wrote:

    This bug will be fixed in the next version/update of VMWare Server?

    I can't say.  I hope so.

    How many times developers VMWare scan forums?

    It ranges from never every day, according to the developer.

    I applied the work around you suggested, and amazing it worked!

    I'm glad to hear it.

  • Several switches inside the a test sequence

    Hi all

    I'm doing a few stages of switching in a single Multiple digital limit test, so what I did is incorporated all the controls switch in labview. Unfortunately, I got an error when he got to the step with the switching (an error occurred when trying to access device PXI1Slot6
    Another process has already logged to this switch module.).

    Is it possible to disconnect the teststand switch so that the labview vi can be used without interruption, or y at - it another way to do switching multimode in teststand I don't know?

    Thank you for taking the time to read.

    One more thing...

    You can use the adapter of the sequence with a step of the multi-digital.  Then create a sequence that will have several stages.

    I illustrate this in the sequence file attached.

    Let me know if you have any questions.

  • Put virtual machines inside the VMkernel port group

    Hello

    Network for administrators of VMware SIAS layout:

    "You can not put VMs within that group of port because it is made especially for a VMkernel port."

    However, I use ESXi 5.5 and is able to put normal interface of VM inside the vmk port group. (I only created 1 vmk port group so all virtual machines in the same group with the vmkernel interface)

    May I know if this is a new feature, or something is wrong?

    Thank you!

    This may be possible with distributed switches not with standard switches.

  • How to use &lt; C:when test... inside the column in the table of the ADF

    I use ADF table with two columns
    in the first column, I check the Type of document is doc type so I have to use commondlink to download this file, otherwise I need to display only text.

    to this I added
    * < c:when test = "{boolean ($favoriteType eq 'doc')}" > *.
    that does not work.

    Please let me know how to use < C:when test... inside the column in the table of the ADF

    < tr:column sortProperty = "favoriteName" sortable = "true".
    headerText = "#{res ['favorite.favoritename ']}" "
    width = "500" noWrap = "false" >
    < c: choose >
    * < c:when test = "{boolean ($favoriteType eq 'doc')}" > *.
    < tr:commandLink actionListener = "#{bindings.downloadFile.execute} '"
    Text = "#{row.favoriteName} '"
    Disabled = "#{!}" Bindings.downloadFile.Enabled}"/ >
    < / c:when >
    < c: otherwise >
    < af:outputText value = "#{row.favoriteName}" / >
    < / c: otherwise >
    < / c: choose >
    < / tr:column >
    < tr:column sortProperty = "favoriteType" sortable = "true".
    headerText = "#{res ['favorite.favoriteType ']} ' rendering ="true">"
    < af:outputText value = "#{row.favoriteType}" id = "favoriteType" / > "
    < / tr:column >

    Hello

    I do not see, you use a Table of the ADF, but I see that you use Apache Trinidad. JSTL is executed analysis of time then that JSF is to render time, that's why it does not work what you see. Trinidad is a part of tr:switcher, and you can try this. Note that it doesn't ' r allow to change components by rank.

    Frank

Maybe you are looking for

  • I want to increase the size of the history panel

    I just upgraded to v. v. 34 17.0.1. In the old version, I could open the story as a full panel and see the places and dates in chronological order. Now, even if I have the "View > by date and site" option is selected, I can only see sites. Also, when

  • customize the error page

    Hi all, in the past I used "toolkit.zip" to customize the page to display when an error occurs. In the latest version (12), I find this file. Can anyone tell me if it has been removed or what. Thank you very much DCJ

  • How to use a Timer and an event with LIFA/Arduino

    Hello world I feel that my question is going to sound really stupid, but I can't find the solution. I want to use my arduino to do two tasks at the same time. I want to use a while loop with a timer, read my pins in my arduino. It's really easy. But

  • How can I Descreening and adjusts the size of the image target with a HP 8600 n911 premium?

    I recently bought a new HP 8600 n911 premium all-in-one, top of the range HP all in one inkjet printer/scanner.  I can't find the settings that allow me to descreening an image (for example in a newspaper) or to adjust the size of the target image.  

  • Is there an image based restore?

    Original title: restoration of disk images? I just learned the pain once again recover from an accident.  Vista Home Premium on a Dell, several years old, but still useful in nursing along. I remember the old days where there was a ghost on a recover