Trying to figure out whether I can use an ASA cluster in Transparent mode to facilitate VRF based network ??

Hi Guys,
I had to re-post this here because I did not get any comments earlier.. hopefully I'll get something here.. :)
I'm investigating the ways that I can use 2 x ASA (5525x) to accommodate Multi-tenancy situation with overlapping addresses. Unfortunately in this particular scenario we have to stick with 5525x firewalls.
The ASAs are going to be placed in north-south traffic path between 2 routers and these routers need to be configured with multiple VRFs to segregate the traffic for each tenant with overlapping IP subnets ( We are not looking at NAT as a workaround for the time being).
As we know, this ASA model won't support VRFs so we can't use the ASA as a intermediary routing hop and therefore this is not an option.. and using security contexts per VRF seems not scale-able enough (correct me if I'm wrong). So my thinking is that, if we put the ASAs in to the transparent mode and just use the ASAs as a layer 2 interconnect (configured with different VLANs connecting VRFs served by top and bottom routers)  I should be able to go up to maximum of 50 VRFs (since 5525x only supports 200 VLANs).  
I'm also planning to use the 2 ASAs in a cluster mode to aggregate the bandwidth of both ASAs for better throughput.
So I need to clarify following with you guys.. 
1) Can I actually do this or am I missing something.
2) Are there any limitations that I might run in to with this setup
3) Is there anyone out there who's doing the same thing or can you think of a better way to tackle this scenario (with same hardware and requirements)
4) Instead of using clustering, can I use simple Active/Stanby pare and still configure transparent mode and use it that way ?
Appreciate your input.
Thanks
Shamal 

There is a limitation on how many context you can have, which depends on the license you have.  This is quite possible with ASA multi routed mode and even with multi transparent mode.  You can have overlapping ip in each context without the need of using nat as long as you have unique mac address for each sub interface.
Thanks

Similar Messages

  • Using Clustered ASAs in Transparent mode to support VRF based Network ?

    Hi Guys,
    I'm investigating the ways that I can use 2 x ASA (5525x) to accommodate Multi-tenancy situation with overlapping addresses. Unfortunately in this particular scenario we have to stick with 5525x firewalls.
    The ASAs are going to be placed in north-south traffic path between 2 routers and these routers need to be configured with multiple VRFs to segregate the traffic for each tenant with overlapping IP subnets ( We are not looking at NAT as a workaround for the time being).
    As we know, this ASA model won't support VRFs so we can't use the ASA as a intermediary routing hop and therefore this is not an option.. and using security contexts per VRF seems not scale-able enough (correct me if I'm wrong). So my thinking is that, if we put the ASAs in to the transparent mode and just use the ASAs as a layer 2 interconnect (configured with different VLANs connecting VRFs served by top and bottom routers)  I should be able to go up to maximum of 50 VRFs (since 5525x only supports 200 VLANs).  
    I'm also planning to use the 2 ASAs in a cluster mode to aggregate the bandwidth of both ASAs for better throughput.
    So I need to clarify following with you guys.. 
    1) Can I actually do this or am I missing something.
    2) Are there any limitations that I might run in to with this setup
    3) Is there anyone out there who's doing the same thing or can you think of a better way to tackle this scenario (with same hardware and requirements)
    4) Instead of using clustering, can I use simple Active/Stanby pare and still configure transparent mode and use it that way ?
    Appreciate your input.
    Thanks
    Shamal 

    Is any expert out there who can answer my query ?. Much appreciated.

  • I'm trying to figure out how I can see the equation of the line on the graph I just created. I'm using the OS X Mavericks version of  Numbers.

    I'm trying to figure out how I can see the equation of the line on the graph I just created. I'm using the OS X Mavericks version of  Numbers.

    I think what you're looking for is this. Click chart and in the Series tab under Trendlines you select linear and check Show Equation.
    Unfortunately you can't move the equation from its initial position the way you could with the old Numbers 2.3.
    SG

  • Hi everyone, Im trying to figure out how I can unlock my iphone 4s. I purchased it in Japan under AU KDDI and i finished my contract, im having trouble unlocking it so I can use it in India. Any suggestions?

    Hi everyone, Im trying to figure out how I can unlock my iphone 4s. I purchased it in Japan under AU KDDI and i finished my contract, im having trouble unlocking it so I can use it in India. Any suggestions?

    Only the carrier to which it is locked can do it.  Contact them.
    Please don't use that font.  It makes your post difficult to read and people are less likely to take time to read it and help you.

  • CVP call server logs - Hi All, I am trying to figure out whether caller party(End User) hangup the call first or UCCE Agent

    CVP call server logs
     Hi All,
    I am trying to figure out whether caller party(End User) hangup the call first or UCCE Agent.
    Attaching CVP call server Logs& UCCE TCD& Route Call Details for your reference.

    From the CVP logs, it can be determined which side disconnected the call first. For each call, CVP keeps track each call leg. From Inbound Gateway to CVP is INBOUND leg, rest are OUTBOUND leg. You can then look at which leg the SIP BYE message is received first.
    Since you have very basic log enabled, you will not see the exact SIP message. But it can be determined by the outcome of the message. Here is the snippet of the log during the disconnect:
    Line 3766: 3083689: 10.180.245.43: Sep 12 2014 12:21:11.293 -0700: %CVP_8_5_SIP-7-CALL:  {Thrd=DIALOG_CALLBACK.6} CALLGUID = CBCCDD8539E811E4A3E2CCEF48565980 LEGID = CC65CE04-39E811E4-87DFD7D1-64B198F2 - [INBOUND] DURATION (msecs) = 25610 - DIALOG TERMINATED. Reason: Q.850;cause=16
    Line 3768: 3083690: 10.180.245.43: Sep 12 2014 12:21:11.293 -0700: %CVP_8_5_SIP-7-CALL:  {Thrd=DIALOG_CALLBACK.6} Sending BUS MSG:>>HEADERS: (JMSType)=MsgBus:CALL_STATE_EVENT (JMSDestination)=Topic(CVP.SIP.CC.EVENT) (JMSTimestamp)=1410549671293 >>BODY: callguid=CBCCDD8539E811E4A3E2CCEF48565980 RouterCallKey=6472 RouterCallKeySent=true causecode=1 timezone=America/Los_Angeles RouterCallKeySequenceNumber=0 version=CVP_8_5 labeltype=1 RouterCallKeyDay=151099 calldate=Fri Sep 12 12:21:11 PDT 2014 label=190376 localOffset=-420 eventid=6 calllegid=CC65CE04-39E811E4-87DFD7D1-64B198F2  >>STATE: isTabular=false isWriteable=true cursor=-1  
    The first Termination message came on the INBOUND leg which is the PSTN. That means, PSTN side disconnected the call first.
    Hope this helps.
    Abu

  • I am trying to figure out how I can get my library transferred to the Honda Accord 16gb hard drive?  I have purchased music of off I tunes and do not have the physical CD.  Anybody with any suggestions on how this can be done?

    I am trying to figure out how I can transfer my library to my new 2014 honda accord that has an internal 16gb hard drive.  The manual for the car says that it needs to be original CD's but I have purchased alot of the albums/songs I have from I tunes therefore not having the original CD.  Can someone help me with this as I dont want to load each CD into the player to record and have some albums that I purchased off of I tunes that I would like to be on the hard drive.
    Thanks Any Help is appreciated.

    If Honda says you need the original CDs, you need the original CDs.

  • TS3581 I'm using a XM skydock system and I'm trying to figure out why I can't hear my phone through my radio. I can hear my phone ring through the radio. I also hear the music from the iphone.

    I'm using a XM skydock system and trying to figure out why I cant hear my phone calls through ny radio. I can hear it ring, i can also hear my music play...

    What is selected under the Photos tab for your iPhone sync preferences with iTunes?
    If the videos are in an iPhone compatible format and are in a folder of photos selected to be transferred to your iPhone under the Photos tab for your iPhone sync preferences with iTunes, do you also have Include Videos selected under the Photos tab?
    Or if the videos are in an iPhone compatible format, they need to be in your iTunes library and can be selected under the Movies tab for your iPhone sync preferences with iTunes to be transferred to your iPhone.

  • I am trying to figure out where I can type my papers? Like word for mac?

    I need to figure out where I can trype my papers. Do I have to download something extra? Word?

    You can get LibreOffice and much much more here:
    LibreOffice 4.0.0.1
    Apple does not yet have the software market locked up.
    LibreOffice opens and saves in open standards, .doc and most formats available, unlike Pages. This gives you a much better chance of recovering your work should something go wrong or should Apple decide to abandon Pages because it isn't interested anymore.
    Peter

  • Can anyone help me figure out if i can use my droid to get online with lapdown ?

    I am having a very hard time with a certain problem. i am trying to cut cost at home and would like to get rid of my internet service with cable co. i am under the impression that i can use my droid to connect laptop to use online. can anyone please help me step by step with this if it is possible? please email me... thanks, kathryn

    what do you think of this...
    The FCC orders Verizon Wireless to pay
    $1.25 million as settlement to the Treasury. This is just a parcel of the
    carrier’s $6.9 billion
    revenue
    it has gained from the mobile market in the second quarter of this year. The
    company is also ordered to notify Google that the objection to the tethering
    apps from the Play Store is now off. This means that when new tethering apps
    become available in the app store, everyone would be able to download and use
    them without additional fees even if they are Verizon
    customers.
    Verizon will, of course, continue to
    charge its customers with their overall data use every month so for those who
    have capped data will not be able to enjoy tethering functionality but the ones
    with unlimited data plans are the luckiest. The FCC’s ruling made everybody a
    winner; consumers under the network would be able to share their connection, app
    developers don’t fear of being blocked when releasing tethering apps, and
    Verizon can attract more customers to subscribe to their unlimited
    plan.
    Read more at http://thedroidguy.com/2012/08/fcc-mandates-verizon-to-allow-tethering-apps-on-android-smartphones/#4ea8gkhCZMf0ypQ5.99

  • I am trying to figure out how I can have a "main" itunes account for all purchases, but have seperate accounts for my children so they can use iMessage and other features of iPod touch. Also, they would be able to download free items.

    Can you have one install of iTunes on a PC or Mac, but have multiple Apple IDs tied to it?

    You can't have multiple IDs associated with an itunes account, but you can have one ID one 1 device and another one, but currently its impossible to merge accounts.

  • Trying to figure out easiest formula to use in iOS Numbers

    To all you smart function Guru's. Looking for help to see if this can be done.
    All help will be greatly appreciated here. Using Numbers on the iPad.
    My situation. In the "Pick Up" box I select a location from a drop down, it then puts in a numerical figure in the "HOE 1" box from the HOE Chart. (Easy part).
    Now once I "Pick Up" I then select a "Drop Off" location (it will only be a few different locations) and want that to pick a numerical figure, depending on "Pick Up" and "Drop Off" location selected, from the HOE Chart and input the numerical value into HOE 2 box. This is the problem. I want it to look also at the "Pick Up" location to select the correct altitude for the "drop off". i.e. I depart my standard location and I pick up from  Citrus Mem Hosp and I am going to Shands (as in  the picture) I need it to select the Altitude from the HOE Chart that corresponds to the Drop Off leg (HOE 2).
    Pick Up Location selects from B Column (HOE Chart) HOE 1 altitude is picked from D column (HOE Chart).
    Drop Off HOE 2 would be picked from E, F or G Columns (F & G not completed yet) of the HOE Chart.
    I am not a novice in using Excel or charts but am a novice when it comes to complex functions. Please spell out some of the function with your reply.
    Again ALL Help is greatly appreciated.

    Wayne,
    Thanks for helping and I think you are on the right track. The formula works in iOS Numbers with a little tweaking with 1 problem. Why Apple can have the programs work the same is beyond me but hey, I am a Windows guy so I won't complain.
    The problem is that, and its probably my fault in the way I asked. I need the Drop Off (Table "Location" B2) to select from the HOE Chart either Columns E, F, or G (possibly an H in the future) of the Pickup Locations ROW (Highlighted in Blue for this example)
    example.
    I leave my location (always the same) and go to Pickup Location = Citrus Mem Hosp. HOE 1 gives me altitude from highlighted Row + Column D (HOE Chart).
    Now the complex part (to me)
    I depart Citrus Mem Hosp (pick up location) and I am going to Shands (Column E (HOE Chart)) so I select that from my drop down list in "Drop Off" location(location table), I need HOE 2 (hoe table) box to give me the Altitude for Row (Citrus Mem Hosp) + Column E (Shands Column). If I select Orlando or Tampa Columns I would need it to select that altitude for the same Row.
    I hope this explains it a little better and the pictures outline it a little more.
    Your equation selected (once I input the correct Hospital name in my Drop off Location list) the altitude as if I was going from that location to GNV (Shands).
    I hope this can be done as it would make our lives a lot easier and help us get in the air quicker.
    Again Thank you for your help and time.
    P.S. We just moved to Florida from Corpus Christi. Been up in your parts quite a few times.

  • Help trying to figure out which devise to use

    have used tungsten for years. want a phone and pda combo for business app. the ones i tried in the sprint store will not open my quickbooks online web pages. is there somthing that needs to be added? i am not a teckie but would like the freedom of doing business in the field.
    Post relates to: Tungsten E2

    dwteam wrote:
    the ones i tried in the sprint store will not open my quickbooks online web pages. is there somthing that needs to be added?
    The QuickBooks online site says:
    You get anytime, anywhere access from any Internet-connected PC or Mac.1 And, you can even view your company data from an iPhone™ or Blackberry®.2
    1 Requires Internet Explorer 6 or higher, Firefox for Windows or Safari for Mac.
    2 Standard cell phone fees apply. 
    It sounds as though Intuit has created mobile apps for the iPhone and Blackberry OS, but nothing specific for PalmOS, Windows Mobile, or Palm's webOS. As far as browser access, which devices did you try? Did the site just fail to work correctly, or does it say the mobile browser was not supported?
    You could try the QuickBooks Online support options for advice on devices other than the iPhone and Blackberry if you prefer. If you find a Palm-friendly solution, please post back for future reference.

  • •Ever since my fiancee had his Ipod touch malfunction my computer will not allow me to reinstall Itunes or any other kind of installer? I was on the web for ten hours trying to figure out what I can do!

    I am not sure what it is that happened?
    But, I think it was his Ipod that messed the computer installer up!
    I can download Itunes, but I am not able to run it?
    I also cannot run any other kind of programs on my computer since this had happened!
    I finally got his Ipod to show the usb and the Itunes ogo but now can't re-install the Itunes to restore his Ipod!
    If anybody has any ideas I will keep trying!
    Thank you for reading!

    Did you try the suggestions mentioned in this article? iOS: Device not recognized in iTunes for Windows
    Did you already try to remove all Apple related software and install iTunes again, as described in this article?
    Removing iTunes, QuickTime, and other software components for Windows Vista

  • I deleted an email account not knowing that my notes would delete too from iPad and am trying to figure out if icloud can retrieve them for me

    I deleted an email account not knowing that it would delete my notes section as well can iCloud retrieve it?

    You can check at icloud.com, sign in

  • HT1920 hello my name is juan and i am trying to figure out why i can't buy any music telling me to get ahold of you guys to move forward?

    hello

    It's difficult to determine what it is you're asking, but if you've been told to contact the iTunes Store to complete the transaction, you will need to do what it says, contact iTunes support. Click the Support tab above, then the link in the Contact Us area and you'll be guided.
    Regards.

Maybe you are looking for