<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need advice on converting ASAs from active/standby to active/active in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183087#M1075717</link>
    <description>&lt;P&gt;If you have NAT enabled,&amp;nbsp; i prefer to split the load, with PBR and Failover Option.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Nov 2020 22:28:18 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2020-11-12T22:28:18Z</dc:date>
    <item>
      <title>Need advice on converting ASAs from active/standby to active/active</title>
      <link>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183015#M1075708</link>
      <description>&lt;P&gt;We are using a pair of ASA 5585Xs in active/standby mode (single context, routed mode). We have a 6509e for our core switch, which connects directly to the ASAs, and the outside interfaces on the ASA connect to a single 3850 switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This setup has been working fine, but lately our bandwidth needs have been growing extremely rapidly. The active firewall seems to be struggling around 2.3 Gbps and by the time the inbound traffic gets to 3 Gbps network performance is very noticably degraded.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the ASA5585Xs are now about 2 years end-of-sale, we are in the process of ordering a pair of Firepower 4115s to replace them. These are going to take about 4 weeks before they arrive and can be installed. In the meantime, I need to find a temporary solution to alleviate the occasion network slow downs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been looking into converting the active/standby setup to active/active, so that both can pass traffic. I think I understand the general idea of how the ASA config is done. My questions:&lt;/P&gt;&lt;P&gt;- when the config changes are done, will I be left with two contexts on both firewalls with nearly the identical configuration (except for the ip addresses)?&lt;/P&gt;&lt;P&gt;- with active/active firewalls, how is the load balancing actually done? A FHRP like GLBP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also looked at ASA clustering, but it looks like we would need to purchase a license to do that, and everything ASA 5585X is end-of-sale, so I'm not sure where we would get one from.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any easier alternatives to this to tide us over for the next 4 weeks would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 19:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183015#M1075708</guid>
      <dc:creator>spfister336</dc:creator>
      <dc:date>2020-11-12T19:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Need advice on converting ASAs from active/standby to active/active</title>
      <link>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183030#M1075709</link>
      <description>&lt;P&gt;Personally, i do not believe it will resolve your bandwidth issue, Active / Active means active /standby per context.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That means Group A&amp;nbsp; Active on FW1 / FW2 Standby GroupB FW1 Standby / FW2 Active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes correct you can use 2 devices, but they terminate at the same place of exit point right? what advantage you getting here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;not sure what SSP you have look at the below limitation ( you can have many contexts, but box capacity same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-730903.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-730903.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 20:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183030#M1075709</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-12T20:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Need advice on converting ASAs from active/standby to active/active</title>
      <link>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183033#M1075710</link>
      <description>&lt;P&gt;I don't think it's a bandwidth issue. I think it's a processor power issue. I'm just trying to spread the load between the two devices somehow. All of our interfaces are 10 GE and we have 5 Gbps upstream bandwidth. Both boxes have SSP-20s. I've thought about upgrading those, but they'd have to be used equipment and I'm not sure the customer would want to spread money to upgrade with the new firewalls on order.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 20:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183033#M1075710</guid>
      <dc:creator>spfister336</dc:creator>
      <dc:date>2020-11-12T20:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Need advice on converting ASAs from active/standby to active/active</title>
      <link>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183059#M1075712</link>
      <description>&lt;P&gt;Personally, i really do not see the advantage, kind of effort you trying to help customers. making them Active/Standby to Multi Context, required downtime and planning, by the time you do all prep work and maintenance window for this task. you will get a new kit arrived on site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Until unless its a more pressing issue, you need to identify the bottleneck and manage the crisis, plan for code migration from ASA to FTB and plan ready for the new kit goes in as soon as it arrives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you still like to test - the best option you can easy way is to break the Active / Standby to new Standalone, Route the traffic by removing standby ASA make another standalone. this way you have less downtime&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure is this make sense / but i prefer to do this, rather re-do everything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 21:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183059#M1075712</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-12T21:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Need advice on converting ASAs from active/standby to active/active</title>
      <link>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183063#M1075713</link>
      <description>&lt;P&gt;I'd rather not change anything before getting the new hardware in, but I also don't want to be getting daily complaints. I may try making them both standalone as you suggest. Currently, there is one static default route to the primary firewall address. Would I need to set up some sort of FHRP?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 21:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183063#M1075713</guid>
      <dc:creator>spfister336</dc:creator>
      <dc:date>2020-11-12T21:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need advice on converting ASAs from active/standby to active/active</title>
      <link>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183087#M1075717</link>
      <description>&lt;P&gt;If you have NAT enabled,&amp;nbsp; i prefer to split the load, with PBR and Failover Option.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 22:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-advice-on-converting-asas-from-active-standby-to-active/m-p/4183087#M1075717</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-12T22:28:18Z</dc:date>
    </item>
  </channel>
</rss>

