ASA to Layer3 switch

Hello Niel

Concerning your update, yes, you’ve corrected the next-hop IP address for the routing in the ASA, and that has resolved the routing problem, so that’s great.

Concerning a high availability configuration, there are various options to use. You can use an Active/Standby configuration with two ASAs as seen in the ASA Active/Standby lesson, or an Active/Active failover scenario as shown in the following Cisco documentation:

From this, you can connect the ASAs to two switches using some gateway redundancy protocol such as HSRP or VRRP. Or, you can employ EtherChannel to two different switches, or you can even stack those two switches and make them operate as one with two EtherChannels to each ASA.

It all depends upon your specific topology, the equipment you are using, and the capabilities of that equipment. It also depends upon where routing is taking place. There’s no clear cut answer, however, there are advantages and disadvantages to each option.

I hope this has been helpful!

Laz