Installing ASA FWSM into VSS Switches

I am getting ready to install a pair of ASA FWSM modules (WS-SVC-ASA-SM1) into a pair of VSS 6509-E switches on our College campus network. The VSS chassis' have dual ten GigE connections to our data closets and consist of primarily wired and wireless campus network users. Apparently there several options of how to install the FWSM modules and several options of active/standby configurations in a VSS environment. I was wondering if anyone has had experience doing this and if they could share with me their experiences? And if there is a best practice for this type of deployment i.e. transparent mode vs. non-transparent mode (no NAT on these firewalls), load balancing issues, active/standby deployment, etc.? Any information would be greatly appreciated.

There's not a whole lot of ASA Service Module deployments out there that I've seen. Most customers are opting for the 5585-X in that performance / price range.
If you haven't already looked at it, there are some general principles outlines in the document "Service Module Design with ACE and FWSM". Much of the FWSM info there can be applied directly to the ASA SM.
A lot depends on the environment into which they will be integrated so it's hard to answer the question in a general sense. I would say that I have seen transparent mode on perhaps 5% of the ASA implementations of any kind that I have seen.
The ASA SM does not support clustering, so a pair is limited to HA mode. Whether you use Active/Standby or Active/Active depends partly on whether you have multiple contexts and how much complexity you feel comfortable adding.
Hope this helps. 

Similar Messages

  • WLC 4402 LAG connection to 2 different chassis of 6509 VSS switch system

    Hi,
    I have inherited a 6509 VSS switch system as the network core and have the task of ensuring proper redundancy and redesign of the directly connected data center devices.  One of the connected devices (WLC 4402) physically appears to be connected to both switches - the WLC is in the same rack as VSS-Chassis1 so I can trace the fiber from WLC port 1 to gi1/1/22, the other fiber from the WLC port 2 goes into the floor and presumably over to VSS-Chassis2 gi2/1/22 (there is fiber connected there, I have link lights on both sides, and the port channel, Po200, on the VSS switch which is configured on gi1/1/22 is also configured on gi2/1/22).  My question pertains to the CDP neighbor output I get on the VSS switch: (truncated to include just the WLC)
    NCMECHQWiFi1     Gig 1/1/22        137               H    AIR-WLC44 Gig 0/0/2
    NCMECHQWiFi1     Gig 1/1/22        137               H    AIR-WLC44 LAGInterface0/3/1
    NCMECHQWiFi1     Gig 1/1/22        137               H    AIR-WLC44 Gig 0/0/1
    It looks like both WLC ports are physically connected to Gi1/1/22, which they are quite obviously not.
    This is confirmed on the WLC's sho cdp entry all output:
    (Cisco Controller) >show cdp entry all
    Device ID: ncmec-vsscoresw1.ncmec.org
    Entry address(es): 100.1.0.254
    Platform: cisco WS-C6509-E,  Capabilities: Router Switch IGMP
    Interface: LAGInterface0/3/1,  Port ID (outgoing port): GigabitEthernet1/1/22
    Holdtime : 160 sec
    I believe that the multi chassis etherchannel is set up correctly on the VSS:
    vsscoresw1#sho run int gi1/1/22             
    interface GigabitEthernet1/1/22
    description WLC-Management
    switchport
    switchport trunk encapsulation dot1q
    switchport mode trunk
    switchport nonegotiate
    channel-group 200 mode on
    end
    vsscoresw1#sho run int gi2/1/22
    interface GigabitEthernet2/1/22
    description WLC-Management
    switchport
    switchport trunk encapsulation dot1q
    switchport mode trunk
    switchport nonegotiate
    channel-group 200 mode on
    end
    vsscoresw1#sho run int po200
    interface Port-channel200
    description WLC-Management
    switchport
    switchport trunk encapsulation dot1q
    switchport mode trunk
    switchport nonegotiate
    end
    And yet when I show the details of port channel 200, I expect to see "mode on" but get instead see LACP which is unsupported on the WLC:
    vsscoresw1#sho etherchannel 200 detail
    Group state = L2
    Ports: 2   Maxports = 8
    Port-channels: 1 Max Port-channels = 1
    Protocol:    -
    Minimum Links: 0
                    Ports in the group:
    Port: Gi1/1/22
    Port state    = Up Mstr In-Bndl
    Channel group = 200         Mode = On      Gcchange = -
    Port-channel  = Po200       GC   =   -         Pseudo port-channel = Po200
    Port index    = 0           Load = 0xFF        Protocol =    -
    Mode = LACP
    Age of the port in the current state: 180d:19h:47m:01s
    Port: Gi2/1/22
    Port state    = Up Mstr In-Bndl
    Channel group = 200         Mode = On      Gcchange = -
    Port-channel  = Po200       GC   =   -         Pseudo port-channel = Po200
    Port index    = 1           Load = 0xFF        Protocol =    -
    Mode = LACP
    Age of the port in the current state: 180d:19h:47m:02s
                    Port-channels in the group:
    Port-channel: Po200
    Age of the Port-channel   = 354d:12h:47m:27s
    Logical slot/port   = 46/19          Number of ports = 2
    GC                  = 0x00000000      HotStandBy port = null
    Port state          = Port-channel Ag-Inuse
    Protocol            =    -
    Fast-switchover     = disabled
    Load share deferral = disabled  
    Ports in the Port-channel:
    Index   Load      Port          EC state       No of bits
    ------+------+------------+------------------+-----------
    0      FF       Gi1/1/22                 On   8
    1      FF       Gi2/1/22                 On   8
    Time since last port bundled:    173d:17h:06m:34s    Gi2/1/22
    Time since last port Un-bundled: 173d:17h:06m:34s    Gi2/1/22
    Last applied Hash Distribution Algorithm: Fixed
    >>>  So my question, arising at least partly from the apparently misleading CDP information, is this:  How can I confirm that the WLC is correctly dual homed to both core switches? (short of tracing the cable)  I ask because there are several other devices (not WLCs) that need to have the dual homed connections confirmed.
    I tried a layer 2 trace route but for all macs associated with the WLC, the trace abborts with the error "Device has Multiple CDP neighbours on destination port."
    Thanks in advance!
    Sue

    PS:  It is critical that I confirm the redundancy, since as a part of the data center redesign we will be moving the second VSS chassis to the same rack with the first to simplify the dual connections.  I need to verify all the redundant connections before I take it offline and move it.  Thanks!

  • Upon entering a LV project file into VSS, all files in the project are left out. Only the project shell and settings enter VSS. Any idea why?

    Upon entering a LV project file into VSS, all files in the project are left out. Only the project shell and settings enter VSS. Any idea why?
    Solved!
    Go to Solution.

    Chuck72352,
    Hello! It is my understanding that you need to add the individual files to the Source Code Control along with the .lvproj file.
    Here is a great deal of information on Source Code Control Practices in LabVIEW.
    Ben Sisney
    FlexRIO V&V Engineer
    National Instruments

  • I have a Macbook pro 2009 with Snow Leopard.  Which system can I install without running into complicated problems which I will not be able to solveby myself? (Mountain Lion, Mavericks, Yosemite?)

    I have a Macbook pro 2009 with Snow Leopard.  Which system can I install without running into complicated problems which I will not be able to solve by myself- a person with limited problem solving abilities. (Mountain Lion, Mavericks, Yosemite?)

    It will make it easier to help you w/ your problem to know the  size and RAM installed.
    "Yesterday I couldn't update the maps on my Garmin because it said the OS I had wouldn't work"
    What OS will your Garmin work with? Funny there was someone else that did that and upgraded to Yosemite and regretted it.
    I'd say Lion if your Garmin is compatible.
    Both Lion and Mountain Lion are downloadable from the Apple Store:
    http://store.apple.com/us/product/D6106Z/A/os-x-lion
    http://store.apple.com/us/product/D6377Z/A/os-x-mountain-lion
    The OSs will get more resource hungry the higher you go.

  • How do I install an SSD into my 2007 Macbook?

    Hi All,
    I did some searching online, but couldn't conclusively find a step-by-step procedure to installing an SSD into my 2007 Santa Rosa Blackbook.
    My mac has been running slow, and I've upped the memory to 2gb (I will be upping it to 4 shortly), but also wanted to consider an SSD as well. I know how to physically install the SSD, but my questions are:
    Will it work with my specific macbook?
    I have Snow Leopard 10.6.8, will that have this "TRIM" update for SSDs?
    Do I have to contact Apple for a Snow Leopard boot disk?
    With my mobo, is my speed limited to SATA I? I heard about a possibly way to up it to SATA II but not sure about this...(is it true?)
    I heard we have to format SSDs before we can use them. If I manage to get a boot disk from Apple, can it handle the formating after turning it on with the new hard drive (through BIOS)
    Lastly, any make and model you guys suggest? There's no point for me to get at SATA III, so I don't want to spend a lot of money. Let's assume 80 - 120 gb for now.
    Any help or step-by-step instruction would be terrific!
    Thanks a bunch!!

    Hey Eric,
    Thanks for the link! Though, I actually know how to physically install the SSD. It was my other questions that I'm getting puzzled by. Any ideas on those?
    EDIT: Actually, it answered one of the questions about transferring my data, so cool!
    Thanks!

  • HT3986 I have installed windows 7 into my macbook pro 15 inch with lions.  This computer is the current 2.2 GH i7 chip with 500 GB HD.  Now, how do I install the drivers.  When I started boot camp, the system prompted me to create a CD.  What do I do with

    I have installed Windows 7 into my Macbook Pro 15 inch with Lions as operating system.  (current model with 2.2 GHz i7 processor, 500 GB HD ad 5400 rpm).  When I started with boot camp, the system promped me to create a disc, which I presume is for the drivers for windows 7.  Now windows is intalled.  What do I do with the CD that the system created for me?  Also, why does the system automatically start in Win7 instead of Lion.  I need to pression the option key to have it start in OS X.  I thought it was supposed to be the opposite.

    Insert it while you are in Windows, if it does not autostart run setup.exe.
    Choose your startup disk using Apple>System Preferences>Startup Disk (in OSX) or Control Panel>Boot Camp>Startup Disk (in Windows)

  • Can I install an SSD into my MSI GE620DX laptop?

    Can I install an SSD into my MSI GE620DX laptop?
    Couldnt find any information on the site or the manual about that, Im thinking of ordering an SSD but I dunno if I can put whatever type of SSD in there.
    The 128gb SSDs in sweden are just in my price-range right now and it would be reeeally nice to check out how fast this thing can run... :D.
    My laptop is the i5-2410m-version.
    Reason I wanna upgrade to SSD is obviously because of improved performance but also that I can probably turn the current built-in HDD into an external device maybe? I am setting up my laptop for music production and I just want a fast SSD for windows,software. Other HDDs for recording audio, having projects on them and so forth.
    The HDD in mine is the 500gb/7200RPM one, I hope I can turn it into an external somehow(read that you can somewhere and I assume most drives can be turned into external HDDs???)

    Shouldn't be any problem. You can replace the 2.5" HDD of your notebook with any 2.5" SSD. Be aware that you need to reinstall Windows unless you have a software to clone the current on the SSD.
    With an external USB hdd case you can use the HDD as an external drive. However if you erase the current partitions you will loose the possibility of using the F3 recovery with the HDD reinstalled if the Windows on the SSD gets destroyed by a virus or similar problems.

  • I need help on my MacBook Pro. Recently I've deleted another partition of my disk from the disk utility and I found out that my disk capacity wasn't get into the normal one which is 750GB. Meanwhile I installed window 7 into the partition disk.

    I need help on restoring my disk capacity back to normal. I installed window 7 into the partition disk through bootcamp and I deleted it from disk utility. After I erase the partition disk,I get my capacity to 499GB but not 750GB. Do I need to reinstall my MacBook or something to do with the restoring?

    Welcome to the Apple Support Communities
    Rodney Lai wrote:
    I installed window 7 into the partition disk through bootcamp and I deleted it from disk utility
    You shouldn't do it. You have to erase the Windows volume with Boot Camp Assistant, so it will restore the space onto the OS X volume and that volume will have 750 GB.
    As you did it with Disk Utility, you have to resize your OS X partition manually:
    1. Open Disk Utility, select your hard disk at the top of the sidebar, and go to Partition tab.
    2. You will see a bar with Macintosh HD. You have to click it at the bottom right corner and drag it to the end of the bar, so Macintosh HD will use all the space of the hard drive, and press Apply.
    3. Close Disk Utility and your OS X partition will have 750 GB

  • How to install Windows XP into a Flash Drive?

    I would like to install Windows XP into my flash drive. Not boot from the flash drive and install into my PC. I've searched extremely hard on the internet and found the other thing around and I tried what I could. Any suggestions? (Here's what I tried: Creating partition tables. Install using VMware. Using different formats.

    Thanks for the tips. I was able to install Windows XP and boot from the SATA drive by using these options and setting the appropriate boot device selections...
    Legacy Mode
    ATA Configuration - PATA only
    SATA Keep enabled - yes
    PATA Keep enabled - yes
    PATA channel selection - both
    Combined Mode Option - S-ATA 1st Channel
    S-ATA Ports Definition - P0 - 3rd./P1 - 4th.
    I just wasn't sure if I was really getting "SATA" performance, etc. without specific drivers.
    Thanks again.
    Bob (ll1951md)

  • How to install Oracle 10g into Linux

    Hi All,
    I am a dummy user, this is my first time trying to install the Oracle. I need to install Oracle 10g into my company server, but I ran into issues. I am not sure which package I should download in order to install in my Linux server. Appreciate your advice.
    I ran into this error
    [root@localhost database]# ./runInstaller
    Starting Oracle Universal Installer...
    Checking installer requirements...
    Checking operating system version: must be redhat-3, SuSE-9, redhat-4, UnitedLinux-1.0, asianux-1 or asianux-2
    Failed <<<<
    Exiting Oracle Universal Installer, log for this session can be found at /tmp/OraInstall2009-03-22_06-23-34PM/installActions2009-03-22_06-23-34PM.log
    I tried to download
    1) 10201_database_linux_x86_64.cpio
    2) 10201_database_linux32.zip
    I am running on Linux localhost 2.6.18-8.el5 #1 SMP Fri Jan 26 14:15:14 EST 2007 x86_64 x86_64 x86_64 GNU/Linux
    Linux version 2.6.18-8.el5 ([email protected]) (gcc version 4.1.1 20070105 (Red Hat 4.1.1-52)) #1 SMP Fri Jan 26 14:15:14 EST 2007
    Red Hat Enterprise Linux Server release 5 (Tikanga)

    Thanks Laura, tried the first one and it works. But I guess I am stuck again with the following error. Do I need to access to the server directly? Currently I am just connecting to the server via the VPN connection.
    [oracle@localhost database]$ ./runInstaller -ignoreSysPrereqs
    Starting Oracle Universal Installer...
    Checking installer requirements...
    Checking operating system version: must be redhat-3, SuSE-9, redhat-4, UnitedLinux-1.0, asianux-1 or asianux-2
    Failed <<<<
    Ignoring required pre-requisite failures. Continuing...Preparing to launch Oracle Universal Installer from /tmp/OraInstall2009-03-22_07-11-16PM. Please wait ...
    DISPLAY not set. Please set the DISPLAY and try again.
    Depending on the Unix Shell, you can use one of the following commands as examples to set the DISPLAY environment variable:
    - For csh: % setenv DISPLAY 192.168.1.128:0.0
    - For sh, ksh and bash: $ DISPLAY=192.168.1.128:0.0; export DISPLAY
    Use the following command to see what shell is being used:
    echo $SHELL
    Use the following command to view the current DISPLAY environment variable setting:
    echo $DISPLAY
    - Make sure that client users are authorized to connect to the X Server.
    To enable client users to access the X Server, open an xterm, dtterm or xconsole as the user that started the session and type the following command:
    % xhost +
    To test that the DISPLAY environment variable is set correctly, run a X11 based program that comes with the native operating system such as 'xclock':
    % <full path to xclock.. see below>
    If you are not able to run xclock successfully, please refer to your PC-X Server or OS vendor for further assistance.
    Typical path for xclock: /usr/X11R6/bin/xclock
    [oracle@localhost database]$ echo $SHELL
    /bin/bash

  • I see that i have a problem after installing my new hard drive on my macbook pro mid 2009 version. I put a new hard drive, with all of my information from my old drive installed on it, into the computer. but now have the blinking question mark folder

    i see that i have a problem after installing my new hard drive on my macbook pro mid 2009 version. I put a new hard drive, with all of my information from my old drive installed on it, into the computer. but now have the blinking question mark folder. I see that it means that it isn't reading the new hard drive.
    did i miss a step between transferring all of my information from my old hard drive to the new hard drive and installing the new hard drive into the computer. I believe that i installed properly. it was quite easy.
    thanks for your help

    It means there is no bootable system on the drive. If you still have access to the old drive, then I suggest you boot from it then clone it to the new internal drive. Use OPTION boot to boot from the Recovery HD on the old drive:
    Boot to the Recovery HD:
    Restart the computer and after the chime press and hold down the OPTION key until the boot manager screen appears. Select the Recovery HD and click on the downward pointing arrow button.
         1. Select Disk Utility from the main menu then press the Continue
             button.
         2. Select the destination volume from the left side list.
         3. Click on the Restore tab in the DU main window.
         4. Select the destination volume from the left side list and drag it
             to the Destination entry field.
         5. Select the source volume from the left side list and drag it to
             the Source entry field.
         6. Double-check you got it right, then click on the Restore button.
    Source means the external old drive. Destination means the new internal drive.

  • I reinstalled operating system software on my MacBook Air (Yosemite 10.10.3) and tried reinstalling Adobe Acrobat 9 Pro.  I was able to install the software into my Applications folder but I was unable to enter the serial number or go any further with the

    I reinstalled operating system software on my MacBook Air (Yosemite 10.10.3) and tried reinstalling Adobe Acrobat 9 Pro.  I was able to install the software into my Applications folder but I was unable to enter the serial number or go any further with the installation.  When I click on the Adobe Acrobat icon in the Applications folder, nothing happens.

    Hi Tom,
    kindly check the System requirements | Acrobat family of products—older versions (XI, X, 9)
    For serial number message try: 
    Error "Invalid serial number" | Acrobat 9 | CS4
    Thanks,
    Atul Saini

  • How do you install a gradient into photoshop

    I am needing a refresher on how to install a gradient into photoshop cc.  It is most appreciated.

    Just to let everyone know.  I just remembered.
    Thanks anyway

  • Can i turn my airport express into a switch?

    Can i turn my airport express into a switch?

    A switch is a device with multiple Ethernet ports...and the AirPort Express has only one.
    Can you clarify how you would plan to use the AirPort Express as a "switch"?

  • Installing new HDD into an iMac G5 with SATA

    Installing new HDD into an iMac G5 with SATA and would like to know how to migrate the old system over to the new drive. Can I use a USB2 external drive, move all the old data, then select the new system as the boot system?

    lwolfcc-
    Yes.
    But you might do better with a program like SuperDuper, as it will be sure to copy any hidden files as well.
    Luck-
    -DaddyPaycheck

Maybe you are looking for

  • Why does Motion crash when I try to remove rigged parameter?

    Each time I try to remove a rigged Mask source drop well Motion crashes. This video shows the steps I take. Will you please see if you can recreate the crash? I've tested this on two different Mac computers (Macbook Pro with Lion and Macbook with Sno

  • How do i add songs to a second library?

    I have created a second library but i am having trouble adding songs to it. I am using the latest version of itunes and i have tried several ways of doing it but none seem to work.

  • Pages break up when scrolling

    When I scroll pages in Safari, they 'fracture' - i.e. graphics break up, lines of text split, yet when I try to capture the screen to illustrate the problem it fixes itself. What's going on?? Only noticed this since upgrading to 10.5.4 and Safari 3.1

  • My Gallery Tool in Word:Mac 2008 is not opening ??

    When I click on Gallery I can not access Document elements etc....can someone please help ??

  • Mp4 QuickTime/iTunes AC3 5.1

    Hi, I just convert 300 DVDs to Mp4 with AC3 5.1 with Nero Recode 2, the problem is I have NO sound and thats because QuickTime dont support AC3 5.1 Can some one please help me, I need to play those Mp4 in iTunes, I don´t care if those Mp4 plays in 2