<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA FailOver in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787309#M1098364</link>
    <description>&lt;P&gt;You are so so welcome.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 05 Mar 2023 11:59:20 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-03-05T11:59:20Z</dc:date>
    <item>
      <title>ASA FailOver</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787281#M1098354</link>
      <description>&lt;P&gt;Greetings,&amp;nbsp;&lt;/P&gt;&lt;P&gt;last week i have face a question and i dind'nt get the write answer for it, it is about the configuration of ASA firewall with FailOver,&amp;nbsp;&lt;/P&gt;&lt;P&gt;the question was, when two firewall are connected with fail over, and a originated packet from the inside to the outside the&amp;nbsp; firewall will create a session for this connection and track it , and we assume that the retunred packet is through the seconde firewall ,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;in this senarion how the asa deal with those packet&amp;nbsp; &amp;nbsp;??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* Asa will Drop the packet ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* the State table are synchronous for each other, so the both are awared about all the session state created?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advanced.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2023 10:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787281#M1098354</guid>
      <dc:creator>mellalBrahim</dc:creator>
      <dc:date>2023-03-05T10:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA FailOver</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787285#M1098356</link>
      <description>&lt;P&gt;Yes you are right, status of traffic is exchange between two FW and if return traffic is come through standby it will pass since the standby have xlate and conn of traffic.&lt;BR /&gt;&lt;BR /&gt;case is happened healthy only in&amp;nbsp;&lt;BR /&gt;active/standby failover&amp;nbsp;&lt;BR /&gt;otherwise you have asymmetric and more info. you can see link&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/asa-asymmetric-routing-troubleshooting-and-mitigation/ta-p/3117045" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/asa-asymmetric-routing-troubleshooting-and-mitigation/ta-p/3117045&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2023 11:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787285#M1098356</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-03-05T11:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA FailOver</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787286#M1098357</link>
      <description>&lt;P&gt;&lt;SPAN&gt;and we assume that the retunred packet is through the seconde firewall ,&amp;nbsp; &amp;nbsp; --&amp;lt; this never happens if the HA working as expected, until the ASA HA becomes the split-brain. (means both ASA&amp;nbsp; become Active/Active)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;i would point to some basics below the blog explain how that works, in both Active/Active (means active standby backend for that context) - same case Active / Standby&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://network-insight.net/2015/01/06/asa-failover/" target="_blank"&gt;https://network-insight.net/2015/01/06/asa-failover/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; * Asa will Drop the packet ?&amp;nbsp; &amp;nbsp;( as I mentioned above situation, this happens only when the HA splits - and packet will be dropped)&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* the State table are synchronous for each other, so both are aware of all the session state created?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - if the fail over scenario - Active and Standby aware of full packet flow, when the switchover happens from active to standby, the traffic will seamlessly switch over and no packet drops you see here.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2023 10:53:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787286#M1098357</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-05T10:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA FailOver</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787292#M1098359</link>
      <description>&lt;P&gt;I add link to my previous post.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2023 11:18:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787292#M1098359</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-03-05T11:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA FailOver</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787306#M1098361</link>
      <description>&lt;P&gt;thank for the sharing informations&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2023 11:56:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787306#M1098361</guid>
      <dc:creator>mellalBrahim</dc:creator>
      <dc:date>2023-03-05T11:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA FailOver</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787307#M1098362</link>
      <description>&lt;P&gt;thanks for your reply&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2023 11:56:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787307#M1098362</guid>
      <dc:creator>mellalBrahim</dc:creator>
      <dc:date>2023-03-05T11:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA FailOver</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787309#M1098364</link>
      <description>&lt;P&gt;You are so so welcome.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2023 11:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4787309#M1098364</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-03-05T11:59:20Z</dc:date>
    </item>
  </channel>
</rss>

