I am setting up a highly redundant network and want to run my two ASA's in failover mode – each with a link to a router connected to two different ISP's.
The topology:
My two 2911's are running BGP to the ISPs, and the ASAs are configured in active/passive failover mode.
But how do I configure the links from the ASAs to the routers? They are on 2 different subnets at the moment.
Best Answer
Assuming a single context active/passive failover configuration with the ASAs connecting to the 2911s on unique subnets, you could trunk the links using two subinterfaces and vlan tagging. But the hack is to not have both subinterfaces active at the same time on a single ASA. On the ASA on the left assuming it's active, the first subint would be alive and the second down. After a failover event, the ASA on the right becomes active, and the first subint goes down and the second subint comes up.
Only the relevant subinterfaces' config shown.
ASA
2911-ISP1
2911-ISP2