<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214231#M1021124</link>
    <description>&lt;P&gt;I don't have a diagram, sorry!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hmm, that's what I thought but I got confused by this post &lt;A href="https://supportforums.cisco.com/t5/firewalling/best-practice-for-asa-active-standby-failover/td-p/2565068&amp;nbsp;" target="_blank"&gt;https://supportforums.cisco.com/t5/firewalling/best-practice-for-asa-active-standby-failover/td-p/2565068&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, if there are no monitoring, tracking, or policy configured on the ASAs and one of the interfaces on the active FW were to fail, the firewalls will not failover?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best, ~zK&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2017 22:13:31 GMT</pubDate>
    <dc:creator>zekebashi</dc:creator>
    <dc:date>2017-11-09T22:13:31Z</dc:date>
    <item>
      <title>ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214123#M1021104</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a pair of ASR1002s&amp;nbsp; configured with HSRP. These ASRs are not physically connected. Each ASR has an active Internet &amp;amp; WAN link to the same ISP.&amp;nbsp; Each ASR connects to a&amp;nbsp; L2 downstream switch and each switch connects to an ASA. The ASAs are configured with Failover.&amp;nbsp;HSRP is configured on the link connected to the ISP and another HSRP configured for the link connected to the L2 switches.&lt;/P&gt;
&lt;P&gt;There no tracking nor SLA configured on the ASAs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Primary ASR ----- ISP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Primary ASR ---- L2 switch&amp;nbsp;&lt;/P&gt;
&lt;P&gt;L2 switch ------ Primary ASR&amp;nbsp;&lt;/P&gt;
&lt;P&gt;L2 switch ------ Primary ASA&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Primary ASA --FO--- Standby ASA&lt;/P&gt;
&lt;P&gt;Primary ASA --- L2 switch&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Standby&amp;nbsp;ASR ----- ISP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Standby&amp;nbsp;ASR ---- L2 switch&amp;nbsp;&lt;/P&gt;
&lt;P&gt;L2 switch ------ Standby ASR&amp;nbsp;&lt;/P&gt;
&lt;P&gt;L2 switch ------ Standby ASA&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Standby ASA --FO--- Primary&amp;nbsp; ASA&lt;/P&gt;
&lt;P&gt;Standby&amp;nbsp; ASA --- L2 switch&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is, if the primary/active ASR were to fail,&amp;nbsp; will the standby ASA become the active firewall? I am thinking that since the ISP will be using the HSRP VIP to forward traffic to the standby ASR so traffic will be flowing through the standby ASR downstream to L2 switch and standby ASA!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;~zK&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:42:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214123#M1021104</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2020-02-21T14:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214170#M1021115</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/302926"&gt;@zekebashi&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you could provide a simple draw about the topology would be easier. But, the answer is no. Firewall will not failover due change on the HSRP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;What trigger ASA failover is a problem on the Primary ASA or if the link between then drops and keep alive stops.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 20:16:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214170#M1021115</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-11-09T20:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214231#M1021124</link>
      <description>&lt;P&gt;I don't have a diagram, sorry!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hmm, that's what I thought but I got confused by this post &lt;A href="https://supportforums.cisco.com/t5/firewalling/best-practice-for-asa-active-standby-failover/td-p/2565068&amp;nbsp;" target="_blank"&gt;https://supportforums.cisco.com/t5/firewalling/best-practice-for-asa-active-standby-failover/td-p/2565068&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, if there are no monitoring, tracking, or policy configured on the ASAs and one of the interfaces on the active FW were to fail, the firewalls will not failover?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best, ~zK&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 22:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214231#M1021124</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2017-11-09T22:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214234#M1021131</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;That is correct, you need at least have monitoring on interface for the failover to happen in ASA.&lt;BR /&gt;Cant see the link, it seems to be broken for me.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;br, Micke&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 22:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214234#M1021131</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2017-11-09T22:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214239#M1021141</link>
      <description>Failover Triggers&lt;BR /&gt;The unit can fail if one of the following events occurs:&lt;BR /&gt;• The unit has a hardware failure or a power failure.&lt;BR /&gt;• The unit has a software failure.&lt;BR /&gt;• Too many monitored interfaces fail.&lt;BR /&gt;• The no failover active command is entered on the active unit or the failover active command is&lt;BR /&gt;entered on the standby unit.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/ha_active_standby.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/ha_active_standby.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;br, Micke</description>
      <pubDate>Thu, 09 Nov 2017 22:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214239#M1021141</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2017-11-09T22:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214240#M1021153</link>
      <description>&lt;P&gt;That clears the confusion.&amp;nbsp;Thank you!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best, ~zK&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 22:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3214240#M1021153</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2017-11-09T22:25:45Z</dc:date>
    </item>
  </channel>
</rss>

