Wednesday, July 10, 2019

Cisco ASA design question disaster data center

Hi, I have the following setup. Site A with a running ASA HA cluster and Site B, that replicates alle the internal/external networks from site A over a 1gbit line (redundant). So network wise I'm all set.

My plan was to put two other ASA on site B, Site B becomes a member of Site A ASA cluster and if site A burns down, everything goes through site B.

So I cannot do this with the current HA setup. An active/active/active/active ASA cluster seems to be way out of line (iirc smth like 5gbit DCI) and I cannot control the traffic. Site B traffic should only receive traffic if A goes down.

So I was thinking about contexts, as the most reasonable solution. With i.e. Check Point I can have one or more "contexts". Have a fallback context and then a backup context (which in this case I would put at site B).

Is it possible to run a backup context to the HA context with a third or forth ASA? Or is there an even simpler solution for this?

Thanks



No comments:

Post a Comment