<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874633#M153305</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;it's not a hard prerequisite to configure the standby IPs for failover.&lt;/P&gt;
&lt;P&gt;you'll do this if you want the 'monitor-interface' feature to work properly.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jun 2016 01:05:17 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2016-06-06T01:05:17Z</dc:date>
    <item>
      <title>Cisco ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874627#M153299</link>
      <description>&lt;P&gt;hello team&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;kindly help me for below , i have two cisco ASA 5525 as active / standby &amp;nbsp;, as i know in HA by default all physical interfaces will be monitored but sub interfaces is not monitored&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i have one interface that is ( inside) there is no ip address assigned to it and i have created many sub interfaces ( 100 + ) on that physical interface , &amp;nbsp;i want to confirm , to failover to trigger if inside interface goes down physically ( the failover will happen smoothly or &amp;nbsp;i have to confirgure standby ip on all sub interfaces and to monitor all the sub interfaces )&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874627#M153299</guid>
      <dc:creator>ataur-rahman1</dc:creator>
      <dc:date>2019-03-12T07:50:43Z</dc:date>
    </item>
    <item>
      <title>Your assessment is correct.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874628#M153300</link>
      <description>&lt;P&gt;Your assessment is correct.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 14:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874628#M153300</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-06-05T14:08:42Z</dc:date>
    </item>
    <item>
      <title>hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874629#M153301</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;you'll need to configure the monitoring of 'inside' interface/subinterface on each security context and also the failover policy/criteria, i.e. number of failed interfaces or specify as percentage.&lt;/P&gt;
&lt;P&gt;see helpful link and sample below.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ha_active_standby.html#41939&lt;/P&gt;
&lt;P&gt;ciscoasa/pri/act(config)# failover interface-policy ?&lt;BR /&gt;&lt;BR /&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; &amp;lt;1-216&amp;gt;&amp;nbsp; number of failed interfaces&lt;BR /&gt;&amp;nbsp; &amp;lt;1-100&amp;gt;% percentage of failed interfaces&lt;BR /&gt;ciscoasa/pri/act(config)# failover interface-policy 50%&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 14:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874629#M153301</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-06-05T14:37:01Z</dc:date>
    </item>
    <item>
      <title>thanks john , the monitoring</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874630#M153302</link>
      <description>&lt;P&gt;thanks john , the monitoring of inside ( physical interface is already monitored ) but do i have to monitor the sub interfaces also &amp;nbsp; ( as there is no IP address on inside interface &amp;nbsp;and the status of inside interface is as &amp;nbsp;below)&lt;/P&gt;
&lt;P&gt;my major concern is if &amp;nbsp;inside interface physically goes down the failover should trigger and the production environment shouldnt effect&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;[Interface inside (0.0.0.0): Normal (Waiting)]&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Interface llllllllllll&amp;nbsp;(10.215.218.2): Normal (Not-Monitored)&lt;BR /&gt; Interface pppppp&amp;nbsp;(10.10.10.1): Normal (Not-Monitored)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ASA/pri/act# sh run all monitor-interface &lt;BR /&gt;monitor-interface outside&lt;BR /&gt;monitor-interface inside&lt;BR /&gt;no monitor-interface&amp;nbsp;lllllllllllll&lt;BR /&gt;no monitor-interface&amp;nbsp;pppppp&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 14:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874630#M153302</guid>
      <dc:creator>ataur-rahman1</dc:creator>
      <dc:date>2016-06-05T14:56:00Z</dc:date>
    </item>
    <item>
      <title>yes, you should monitor</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874631#M153303</link>
      <description>&lt;P&gt;yes, you should monitor subinterfaces which corresponds to the configured 'nameif' on each context.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;monitor-interface iii&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;monitor-interface ppp&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;don't also forget the &lt;B&gt;failover interface-policy&lt;/B&gt; command that i mentioned.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 15:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874631#M153303</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-06-05T15:11:25Z</dc:date>
    </item>
    <item>
      <title>appreciated your help :)</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874632#M153304</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;appreciated your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;in addition , should i have to add the standby IPs under all sub interfaces as currently there is no standby IPs configured in any of the sub interface&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 15:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874632#M153304</guid>
      <dc:creator>ataur-rahman1</dc:creator>
      <dc:date>2016-06-05T15:18:40Z</dc:date>
    </item>
    <item>
      <title>hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874633#M153305</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;it's not a hard prerequisite to configure the standby IPs for failover.&lt;/P&gt;
&lt;P&gt;you'll do this if you want the 'monitor-interface' feature to work properly.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 01:05:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874633#M153305</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-06-06T01:05:17Z</dc:date>
    </item>
    <item>
      <title>hi ,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874634#M153306</link>
      <description>&lt;P&gt;hi ,&lt;/P&gt;
&lt;P&gt;is there any limitation of monitoring interfaces , i just checked its 250 &amp;nbsp;( are these limitations of sub interfaces )&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jun 2016 14:47:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874634#M153306</guid>
      <dc:creator>ataur-rahman1</dc:creator>
      <dc:date>2016-06-12T14:47:01Z</dc:date>
    </item>
    <item>
      <title>hi john</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874635#M153307</link>
      <description>&lt;P&gt;hi john&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;the default policy is if single interface goes down , the fail over is triggered ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;ciscoasa/pri/act(config)# failover interface-policy ?&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;configure mode commands/options:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; &amp;lt;1-216&amp;gt;&amp;nbsp; number of failed interfaces&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; &amp;lt;1-100&amp;gt;% percentage of failed interfaces&lt;/EM&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;EM&gt;ciscoasa/pri/act(config)# failover interface-policy 50&lt;/EM&gt;%&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;how can i specify if &lt;STRONG&gt;outside physical interface&lt;/STRONG&gt; (i.e single interface ) &amp;nbsp;goes down the fail over should be triggered&lt;/P&gt;
&lt;P&gt;and inside few sub interfaces goes down ( may be 50%&amp;nbsp;down) then only the trigger should happen&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;the reason behind this question is , if all the subinterfaces are up but the outside interface is down and i have implemented this command then may be the fail over will not happen as i have modified the default policy to 50% of sub interfaces&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;EM&gt;ciscoasa/pri/act(config)# failover interface-policy ?&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;configure mode commands/options:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; &amp;lt;1-216&amp;gt;&amp;nbsp; number of failed interfaces&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; &amp;lt;1-100&amp;gt;% percentage of failed interfaces&lt;/EM&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;EM&gt;ciscoasa/pri/act(config)# failover interface-policy 50&lt;/EM&gt;%&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jun 2016 15:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2874635#M153307</guid>
      <dc:creator>ataur-rahman1</dc:creator>
      <dc:date>2016-06-12T15:21:35Z</dc:date>
    </item>
  </channel>
</rss>

