<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA IPSEC VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-ipsec-vpn/m-p/4404492#M1080848</link>
    <description>&lt;P&gt;Ah OK. since you have multiple context (seen on &amp;lt;5% of the hundreds of ASAs I have worked on) then, no - stateful failover is not supported for the site-to-site VPNs since "IPsec VPN sessions are replicated in Active/Standby failover configurations only." (yours is "Active-Active" in Cisco terms)&lt;/P&gt;</description>
    <pubDate>Tue, 18 May 2021 08:25:18 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-05-18T08:25:18Z</dc:date>
    <item>
      <title>Cisco ASA IPSEC VPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ipsec-vpn/m-p/4404040#M1080830</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we have support for stateful failover of SITE to Site IPSEC tunnel on Multicontext mode.?&lt;/P&gt;&lt;P&gt;I have pair of ASAs 5515-x&amp;nbsp; with 9.8(2)&amp;nbsp;&lt;/P&gt;&lt;P&gt;i read the ASA Document...however still not clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Guidelines for IPsec VPNsMulticontext&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;Context Mode Guidelines&lt;/EM&gt;&lt;BR /&gt;Supported in single or multiple context mode. Anyconnect Apex license is required for remote-access VPN in multi-context mode. Although ASA does not specifically recognize an AnyConnect Apex license, it enforces licenses characteristics of an Apex license such as AnyConnect Premium licensed to the platform limit, AnyConnect for mobile, AnyConnect for Cisco VPN phone, and advanced endpoint assessment.&lt;/P&gt;&lt;P&gt;Firewall Mode Guidelines&lt;BR /&gt;Supported in routed firewall mode only. Does not support transparent firewall mode.&lt;/P&gt;&lt;P&gt;Failover Guidelines&lt;BR /&gt;IPsec VPN sessions are replicated in Active/Standby failover configurations only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-ike.html#ID-2441-000000bc" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-ike.html#ID-2441-000000bc&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 13:11:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ipsec-vpn/m-p/4404040#M1080830</guid>
      <dc:creator>Raj Sh</dc:creator>
      <dc:date>2021-05-17T13:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA IPSEC VPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ipsec-vpn/m-p/4404186#M1080835</link>
      <description>&lt;P&gt;Yes, failover of an ASA HA pair with active site-to-site VPN should not require re-establishment of the VPN tunnel as the state is replicated between the units. (assuming you have a failover state interface configured)&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 16:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ipsec-vpn/m-p/4404186#M1080835</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-17T16:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA IPSEC VPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ipsec-vpn/m-p/4404433#M1080844</link>
      <description>&lt;P&gt;Thank you for your response Marvin,&lt;/P&gt;&lt;P&gt;I want to have an Active - Active setup between 2 buildings within same campus.&lt;/P&gt;&lt;P&gt;ISP1 on&amp;nbsp; FW1&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISP2 on&amp;nbsp; FW2&lt;/P&gt;&lt;P&gt;Context Office1 active on FW1 standby on FW2&lt;/P&gt;&lt;P&gt;Context Office2 active on FW2 Standby on FW1&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both context has site to site IPSEC to same headend HQ and remote offices&lt;/P&gt;&lt;P&gt;And i want statefull failover of S2S IPSEC tunnel&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason for my confusion is below statement&lt;/P&gt;&lt;P&gt;I found this under High availability options - &amp;gt;&amp;nbsp;Frequently Asked Questions About VPN Load Balancing&amp;nbsp;in the below link.&lt;/P&gt;&lt;P&gt;Multiple Context Mode&lt;BR /&gt;Q.Is VPN load balancing supported in multiple context mode?&lt;BR /&gt;A.Neither VPN load balancing nor stateful failover is supported in multiple context mode&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-ha.html&amp;nbsp;" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-ha.html&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 04:48:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ipsec-vpn/m-p/4404433#M1080844</guid>
      <dc:creator>Raj Sh</dc:creator>
      <dc:date>2021-05-18T04:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA IPSEC VPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ipsec-vpn/m-p/4404492#M1080848</link>
      <description>&lt;P&gt;Ah OK. since you have multiple context (seen on &amp;lt;5% of the hundreds of ASAs I have worked on) then, no - stateful failover is not supported for the site-to-site VPNs since "IPsec VPN sessions are replicated in Active/Standby failover configurations only." (yours is "Active-Active" in Cisco terms)&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 08:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ipsec-vpn/m-p/4404492#M1080848</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-18T08:25:18Z</dc:date>
    </item>
  </channel>
</rss>

