<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117202#M1113016</link>
    <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/switches/datacenter/sw/design/vpc_design/vpc_best_practices_design_guide.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/switches/datacenter/sw/design/vpc_design/vpc_best_practices_design_guide.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;page 96&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this how you config ASA HA with NSK vPC what you do I think is not correct&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 27 May 2024 06:25:29 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-05-27T06:25:29Z</dc:date>
    <item>
      <title>ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/5115364#M1112936</link>
      <description>&lt;P&gt;Hi Everyone&lt;/P&gt;&lt;P&gt;Just had a little bit of a confusion with ASA failover and was wondering if anyone had any experience with it&lt;/P&gt;&lt;P&gt;I have two ASA 5500-X in failover mode (Active/Standby), each connected to a different switch in vPC.&lt;/P&gt;&lt;P&gt;I checked the Active and Standby ASA interface MAC addresses on SWT1 and SWT2, and I've got xxx (ASA-Act) MAC on SWT1 as local interface and yyy (ASA-Stdby) MAC on SWT1 as learned via vPC links, but once it fails over, yyy (ASA-Stbdy) becomes local and xxx (ASA-Act) becomes remote on SWT1. it looks like the MAC addresses are changed with failover between ASAs. (I have the same situation when I check by SWT2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 05:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/5115364#M1112936</guid>
      <dc:creator>John.Mayer</dc:creator>
      <dc:date>2024-05-24T05:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/5115382#M1112937</link>
      <description>&lt;P&gt;Is this causing the issue or MAC address changing is the concern here ?&lt;/P&gt;
&lt;P&gt;if this is virtual MAC address that is expected : check below guide :&lt;/P&gt;
&lt;H3 class="p_H_Head2"&gt;MAC Addresses and IP Addresses&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/ha_failover.html#pgfId-1209028" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/ha_failover.html#pgfId-1209028&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 06:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/5115382#M1112937</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-05-24T06:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/5115383#M1112938</link>
      <description>&lt;P&gt;You need to config PO from each ASA to both NSK.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To be more sure can you share your topology&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 06:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/5115383#M1112938</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-24T06:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117130#M1113013</link>
      <description>&lt;P&gt;It makes sense, but the virtual MAC is not necessarily needed, correct?&lt;BR /&gt;My only problem was not being able to tell which physical device is active at the time (the only way to do that is to check the config for failover unit command).&lt;/P&gt;&lt;P&gt;MAC Addresses and IP Addresses in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Failover&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;When you configure your interfaces, you can specify an active IP address and a standby IP address on the same network. Generally, when a failover occurs, the new active unit takes over the active IP addresses and MAC addresses. Because network devices see no change in the MAC to IP address pairing, no ARP entries change or time out anywhere on the network.&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 03:45:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117130#M1113013</guid>
      <dc:creator>John.Mayer</dc:creator>
      <dc:date>2024-05-27T03:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117133#M1113014</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JohnMayer_1-1716781612406.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/219224i959C2092B2E0C52B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JohnMayer_1-1716781612406.png" alt="JohnMayer_1-1716781612406.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 03:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117133#M1113014</guid>
      <dc:creator>John.Mayer</dc:creator>
      <dc:date>2024-05-27T03:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117136#M1113015</link>
      <description>&lt;P&gt;Yes, this is normal. When ASAs are configured in an active-standby high availability pair, the MAC address will change dynamically when failover occurs. This happens whether or not you specify a virtual MAC.&lt;/P&gt;
&lt;P&gt;Behind the scenes, the newly active member of the HA pair sends a gratuitous ARP to assert ownership of the MAC address associated with the primary interface IP addresses for each data plane interface. This minimizes impact on traffic flowing through the devices as the neighbors do not have to wait for their ARP tables to time out or be manually reset to re-establish the flows.&lt;/P&gt;
&lt;P&gt;If there are standby IP addresses configured (these are optional), the newly standby member will do the same for those.&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 04:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117136#M1113015</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-05-27T04:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117202#M1113016</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/switches/datacenter/sw/design/vpc_design/vpc_best_practices_design_guide.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/switches/datacenter/sw/design/vpc_design/vpc_best_practices_design_guide.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;page 96&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this how you config ASA HA with NSK vPC what you do I think is not correct&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 06:25:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117202#M1113016</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-27T06:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117226#M1113017</link>
      <description>&lt;P&gt;Sure that way you going to check which one is active and standby - with show commands.&lt;/P&gt;
&lt;P&gt;Or if you have NMS you can see on the nexus what interface having more traffic that is active unit&lt;/P&gt;
&lt;P&gt;if you have syslog configured you can see the messages when the failover take place - there are number of ways you can detect failover and active unit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 07:22:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/5117226#M1113017</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-05-27T07:22:22Z</dc:date>
    </item>
  </channel>
</rss>

