Hi Everyone and many thanks for the replies. I'm not sure i explained our situation very well, also i'm no network engineer! Original config: One LAN network (192.168.100.0/22) One DMZ Network (172.16.30.0/24) We have two active internet links both being used at the same time We host a web server and ftp server on each link We have an ASA 5510 on each link and the ASAs operate independently BUT both have interfaces IPs on the LAN and DMZ. A PC or server on our LAN could use either internet link by changing the gateway 192.168.100.2 (ASA 1) or we could use the other 192.168.100.10 (ASA 2) This has work fine for years The Plan was simply to replace the ASAs with MX84s I'm using the same interface IPs from the ASAs on the MXs ASA 1 Outside interface IP, LAN Interface and DMZ interface IPs have been set on MX 1 ASA 2 Interface IPs have been set on MX 2 But when we power off the ASAs and power on the MXs (We do power cycle the ISP routers to clear the ARP cache) we start getting major network issues, internal systems that should not be going through the firewalls opening files from file servers, internal voice calls (voip) breaking up, internal management systems crashing after loosing connection to the SQL server!? @ww I hope that explains what the 2nd MX should be doing. @jdsilva No I understand the idea of a warm spare but that is not what we are trying to do we need both to be active and in use at the same time. @Adam Your reply is worrying as it suggests that we can not replicate the original setup with MXs in place of the ASAs do you still think this is the case with the explanation above? Also each ASA had just 3 interfaces and so do the MXs as listed above. @PhilipDAth Yes spot on the two ASAs are completely independent of each other they just sit on the same LAN and DMZ network and that is what we are trying to replicate with the MXs Many Thanks Ian
... View more