1-29
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring a Cluster of ASAs
Configuring ASA Clustering
Purpose
Connect Interfaces on each of 4
ASAs To Switch Ports
Cluster control link TenGigabitEthernet 0/6 and
TenGigabitEthernet 0/7
8 ports total
For each TenGigabitEthernet 0/6
and TenGigabitEthernet 0/7 pair,
configure 4 EtherChannels (1 EC
for each ASA).
These EtherChannels must all be
on the same isolated cluster
control VLAN, for example
VLAN 101.
Inside and outside interfaces TenGigabitEthernet 0/8 and
TenGigabitEthernet 0/9
8 ports total
Configure a single EtherChannel
(across all ASAs).
On the switch, configure these
VLANs and networks now; for
example, a trunk including
VLAN 200 for the inside and
VLAN 201 for the outside.
Management interface Management 0/0 4 ports total
Place all interfaces on the same
isolated management VLAN, for
example VLAN 100.
ASA1
333150
ten0/6
ten0/7
ten0/8
man0/0
ten0/9
ASA2
ten0/6
ten0/7
ten0/8
man0/0
ten0/9
ASA3
ten0/6
ten0/7
ten0/8
man0/0
ten0/9
ASA4
ten0/6
ten0/7
ten0/8
man0/0
ten0/9
Switch
Management
VLAN 100
VLAN 101
port-ch1
port-ch2 port-ch3 port-ch4
Cluster
Control Link
port-ch1
port-ch5
Inside VLAN 200
Outside VLAN 201
Trunk
port-ch1 port-ch1 port-ch1
port-ch2
port-ch2.200 Inside VLAN 200
port-ch2.201 Outside VLAN 201