Cisco ASA Firewall Active / Standby Failover

Hi Art,

Glad to hear you like it!

On the inside I’m using 192.168.1.0/24, R1 is on 192.168.1.1. On the outside we have 192.168.2.0/24 with R2 using 192.168.2.2.

In labs/examples I try to stick to using the number of the router/switch as the IP address.

This example explains how failover works on the ASA but for full redundancy, you’ll need to add some extra components yes. The two switches are still single point of failures, so is R2 on the outside.

The switch on the outside could be replaced with two switches, perhaps in a stack:

https://networklessons.com/switching/cisco-stackwise/

You could then use two routers on the outside, connected to two different ISPs.

If you want to learn a bit more about different ASA designs, you might like Cisco’s Validated Designs. Here’s an example:

Rene