<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Marius,Well, I didn't in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-failover-without-standby-address/m-p/2550759#M234511</link>
    <description>&lt;P&gt;Hello Marius,&lt;/P&gt;&lt;P&gt;Well, I didn't explain correctly. When I told that I put the interface in mode shutdown. I wanted to say that I put in mode shutdown the interface connected to the switch (not in the firewall). It is the same that unplug the cable, but the failover didn't work.&lt;BR /&gt;Then, if you say me that it is mandatory to put the secondary IP address, for me it is sufficient. But I don't find any document in cisco in where explain that it is mandatory.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Sep 2014 19:53:38 GMT</pubDate>
    <dc:creator>adiazcastro19</dc:creator>
    <dc:date>2014-09-30T19:53:38Z</dc:date>
    <item>
      <title>Firewall Failover without standby address</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover-without-standby-address/m-p/2550757#M234509</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello,&lt;/P&gt;&lt;P&gt;We have two ASA5525 in mode failover. Only one them has IP address configuration. For example:&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10px;"&gt;interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;description outside&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 71.210.56.231 255.255.255.252&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;description DMZ_Servicios&lt;BR /&gt;&amp;nbsp;nameif DMZ_Servicios&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.1.1 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;&amp;nbsp;description DMZ_IPSEC&lt;BR /&gt;&amp;nbsp;nameif DMZ_IPSEC&lt;BR /&gt;&amp;nbsp;security-level 40&lt;BR /&gt;&amp;nbsp;ip address 10.110.61.225 255.255.255.240&amp;nbsp;&lt;BR /&gt;!&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10px;"&gt;ASA# sh running-config | i failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface failoverlan GigabitEthernet0/7&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link failoverlan GigabitEthernet0/7&lt;BR /&gt;failover interface ip failoverlan 1.1.1.1 255.255.255.252 standby 1.1.1.2&lt;BR /&gt;!&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10px;"&gt;ASA# sh failover&amp;nbsp;&lt;BR /&gt;Failover On&amp;nbsp;&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: failoverlan GigabitEthernet0/7 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 3 of 216 maximum&lt;BR /&gt;Version: Ours 9.1(2), Mate 9.1(2)&lt;BR /&gt;Last Failover at: 08:10:17 UTC Sep 2 2014&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This host: Primary - Active&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 2348911 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5525 hw/sw rev (1.0/9.1(2)) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (71.210.56.231): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface DMZ_Servicios (192.168.1.1): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface DMZ_IPSEC (10.110.61.225): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (10.115.70.18): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Other host: Secondary - Standby Ready&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 0 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5525 hw/sw rev (1.0/9.1(2)) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (0.0.0.0): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface DMZ_Servicios (0.0.0.0): Unknown (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface DMZ_IPSEC (0.0.0.0): Unknown (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (0.0.0.0): Normal (Not-Monitored) &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;!&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If we put the secondary address in the interface, the failover works fine when we put in mode shutdown the interface (IPSEC or Servicio), but with this configuration, the secondary FW only works when the primary FW is down.&amp;nbsp;&lt;BR /&gt;Although we put in mode &amp;nbsp;monitor the interfaces (Servicios and IPSEC), the secondary FW doesn´t work if we put in mode shutdown the "Ipsec or Servicios" interface.&lt;BR /&gt;We want to know if this configuration works fine with Failover, or it is necesary (mandatory) put the secondary address in the interfaces.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:50:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover-without-standby-address/m-p/2550757#M234509</guid>
      <dc:creator>adiazcastro19</dc:creator>
      <dc:date>2019-03-12T04:50:09Z</dc:date>
    </item>
    <item>
      <title>It is mandatory to put the</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover-without-standby-address/m-p/2550758#M234510</link>
      <description>&lt;P&gt;It is mandatory to put the secondary IP address on the interfaces.&amp;nbsp; Putting the interface in shutdown to test failover is not the way to do it.&amp;nbsp; This puts the interface in Administrative shutdown and the ASA is smart enough to realize this is not a failover situation.&amp;nbsp; What you should do is unplug the cable from the IPsec and/or Servicio ports, then you should be able to see the failover happen.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 06:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover-without-standby-address/m-p/2550758#M234510</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-09-30T06:36:37Z</dc:date>
    </item>
    <item>
      <title>Hello Marius,Well, I didn't</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover-without-standby-address/m-p/2550759#M234511</link>
      <description>&lt;P&gt;Hello Marius,&lt;/P&gt;&lt;P&gt;Well, I didn't explain correctly. When I told that I put the interface in mode shutdown. I wanted to say that I put in mode shutdown the interface connected to the switch (not in the firewall). It is the same that unplug the cable, but the failover didn't work.&lt;BR /&gt;Then, if you say me that it is mandatory to put the secondary IP address, for me it is sufficient. But I don't find any document in cisco in where explain that it is mandatory.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 19:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover-without-standby-address/m-p/2550759#M234511</guid>
      <dc:creator>adiazcastro19</dc:creator>
      <dc:date>2014-09-30T19:53:38Z</dc:date>
    </item>
    <item>
      <title>If memory serves me correct,</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover-without-standby-address/m-p/2550760#M234512</link>
      <description>&lt;P&gt;If memory serves me correct, if you do not have the secondary IP address configured that interface configuration will not be synchronized to the standby ASA.&amp;nbsp; So in the sense that it must be required for the failover pair to be healthy...it is not required.&amp;nbsp; But if you are setting up a failover pair and you do not want the interfaces to be replicated to the standby then there really is no point in setting up a failover pair.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 06:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover-without-standby-address/m-p/2550760#M234512</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-10-01T06:48:39Z</dc:date>
    </item>
  </channel>
</rss>

