<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Failover Deployment in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415861#M307197</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your command output shows you are trying to assign the same &lt;STRONG&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;172.16.19.111 (and .112) &lt;/EM&gt;&lt;/STRONG&gt;address on Context 2 that you have already used in context 1. They need to be unique.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Dec 2013 15:12:14 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2013-12-18T15:12:14Z</dc:date>
    <item>
      <title>ASA Failover Deployment</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415854#M307178</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="color: #666666;"&gt;We ordered two asa5515x that will be deployed in active-active
configuration. 
I've gone through several pages of some example configuration and
deployment options but i cant find what im looking for.

In our current operation, we have one 5520 that has two isp configured to it. How these
two isp are being utilized is based on the traffic destination. By default, all traffic
passes through the primary isp. Some traffic is being routed to the secondary isp based on
the destination address/network. If there is an outage in the primary isp, all traffic
will be routed out on the secondary isp. The same applies if there is an secondary isp
outage, all traffic being routed out on that isp will be routed to the primary isp.

Im looking to deploy these two new asa in an active-active configuration wherein it will
behave the same as what we currently have in our operation. The catch is, all primary isp
traffic will be routed out on the outside interface of the ASA1 and all secondary isp
traffic will be routed out on the backup interface of ASA2. If ASA1 becomes unavailbable,
all primary isp traffic will be handled by ASA2 via its outside interface. The same if
ASA2 becomes unavailable, all secondary isp traffic will be handled by ASA1 via its backup
interface.

Also, in the documents that i have gone through, i can't seem to find if active-active
failover supports the concept of "virtual ip" (like glbp) where in these two ASA shares a
single outside / backup / inside ip address. This is a concern as it may affect our VPN
connections. 
Is there any configuration that can support this deployment or asa can't be configured to support this at all&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Deployment1.jpg" class="jive-image-thumbnail jive-image" onclick="" src="https://community.cisco.com/servlet/JiveServlet/downloadImage/170867/Deployment1.jpg" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415854#M307178</guid>
      <dc:creator>Jon Eyes</dc:creator>
      <dc:date>2019-03-12T03:17:16Z</dc:date>
    </item>
    <item>
      <title>ASA Failover Deployment</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415855#M307181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Active-Active is only applicable for multi-context ASA failover clusters. Single context is Active-Standby only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASAs needing to optionally route to a secondary ISP typically are setup with a backup route and sla monitor job as descrtibed in &lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml"&gt;this document&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Dec 2013 02:56:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415855#M307181</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-12-13T02:56:45Z</dc:date>
    </item>
    <item>
      <title>ASA Failover Deployment</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415856#M307184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Marvin.&lt;/P&gt;&lt;P&gt;Yes, this document served as my guide when i configured the isp failover using a single asa (that is my 5520). The two new asa is already configured in to multiple mode. Im looking to adapt this behaviour in the new asas, with these two asas in ha-mode / cluster (not sure if im terming it correctly, forgive me) as describe above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Going throuhg the sample configuration that i have come across, there this line &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;" ip address [ip] [mask] standby [standby_ip]"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way i understand this is, if ASA1 fails then ASA2 assumes the active role, ASA2 will also assume the standby ip, thus from the public internet perspective, im now at diffirent ip, which is the standby ip. What im looking is ASA2 assume the active role but still uses the original ip. (im referring to an appliance failure here, but isp is still good).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Dec 2013 03:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415856#M307184</guid>
      <dc:creator>Jon Eyes</dc:creator>
      <dc:date>2013-12-13T03:14:55Z</dc:date>
    </item>
    <item>
      <title>ASA Failover Deployment</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415857#M307187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; You're welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The active ASA will always assert the first IP address in your interface configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The standby IP address is used by the standby ASA and is there so that the Active unit in the failover cluster can verify reachability of the Standby unit (assuming that is one of the monitored interfaces for failover purposes). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The standby IP address is not for a "standby" ISP per se. When a failover occurs, the (formerly) Standby unit takes over that first address as it assumes the Active role. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Dec 2013 03:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415857#M307187</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-12-13T03:25:26Z</dc:date>
    </item>
    <item>
      <title>ASA Failover Deployment</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415858#M307190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it. So the virtual-ip im terming here is the first ip declaration in this syntax &lt;SPAN style="font-size: 10pt;"&gt;"&lt;STRONG&gt;&lt;EM&gt;ip address [ip] [mask] standby [standby_ip]&lt;/EM&gt;&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And from my inside network, i should point my core switches' default route to the first declared ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about this idea.&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;PRE style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; overflow: auto; color: #666666;"&gt;By default, all traffic
passes through the primary isp. Some traffic is being routed to the secondary isp based on
the destination address/network. If there is an outage in the primary isp, all traffic
will be routed out on the secondary isp. The same applies if there is an secondary isp
outage, all traffic being routed out on that isp will be routed to the primary isp&lt;/PRE&gt;&lt;P&gt; "&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;PRE style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; overflow: auto; color: #666666;"&gt;The catch is, all primary isp
traffic will be routed out on the outside interface of the ASA1 and all secondary isp
traffic will be routed out on the backup interface of ASA2. If ASA1 becomes unavailbable,
all primary isp traffic will be handled by ASA2 via its outside interface. The same if
ASA2 becomes unavailable, all secondary isp traffic will be handled by ASA1 via its backup
interface.&lt;/PRE&gt;&lt;P&gt; "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Dec 2013 04:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415858#M307190</guid>
      <dc:creator>Jon Eyes</dc:creator>
      <dc:date>2013-12-13T04:04:02Z</dc:date>
    </item>
    <item>
      <title>ASA Failover Deployment</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415859#M307192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You say "&lt;SPAN style="white-space: pre; background-color: #ffffff; color: #666666; font-size: 12px;"&gt;Some traffic is being routed to the secondary isp based on the destination address/network&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;". You do that with a route statement shared across the synchronized configuration file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;For a given Active ASA (or ASA context), you will use routes/interfaces to your primary and secondary ISP. If and only if that ASA (or context) moves from active state on one ASA to active on the other does the other ASA start passing traffic. When it does, it does so exactly like the formerly active unit with the exception that is is going via a physically different appliance and will land in physically different ports in the inside and outside switches. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Nothing changes in the running configuration or routing behavior. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Dec 2013 04:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415859#M307192</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-12-13T04:50:18Z</dc:date>
    </item>
    <item>
      <title>ASA Failover Deployment</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415860#M307195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just picked up my task on this one. im already int this part, not sure if im doing it correctly&lt;/P&gt;&lt;P&gt;In my ASA1, I created two context, C1 and C2. Have already attached corresponding interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are my configuration&lt;/P&gt;&lt;P&gt;----------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sh run context&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;admin-context admin&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;context admin&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; config-url disk0:/admin.cfg&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;context C1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; allocate-interface GigabitEthernet0/0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; allocate-interface GigabitEthernet0/1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; config-url disk0:/C1.cfg&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;context C2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; allocate-interface GigabitEthernet0/0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; allocate-interface GigabitEthernet0/2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; config-url disk0:/C2.cfg&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;-----------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Context-C1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sh run interface &lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface GigabitEthernet0/1&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nameif outside&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;security-level 0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;EM&gt;ip address 208.75.10.1 255.255.255.0 standby 208.75.10.2&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface GigabitEthernet0/0&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nameif inside&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;security-level 100&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ip address 172.16.19.111 255.255.255.0 standby 172.16.19.112&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;Context-C2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sh run interface&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface GigabitEthernet0/0&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nameif inside&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;security-level 100&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;no ip address&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface GigabitEthernet0/2&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nameif backup&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;security-level 0&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ip address 116.50.172.1 255.255.255.0 standby 116.50.172.2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is im receiving this error if im going to configure context-C1 interface g0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ASA1/C2(config-if)# ip add 172.16.19.111 255.255.255.0 standby 172.16.19.112&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ERROR: This address conflicts with another address on net&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to the attachement.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/7/0/171070-Deployment1.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;The Core switches in behind the ASAs are running glbp and the default gateway will be pointed to 172.16.19.111&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any idea how we can proceed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 05:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415860#M307195</guid>
      <dc:creator>Jon Eyes</dc:creator>
      <dc:date>2013-12-18T05:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover Deployment</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415861#M307197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your command output shows you are trying to assign the same &lt;STRONG&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;172.16.19.111 (and .112) &lt;/EM&gt;&lt;/STRONG&gt;address on Context 2 that you have already used in context 1. They need to be unique.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 15:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-deployment/m-p/2415861#M307197</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-12-18T15:12:14Z</dc:date>
    </item>
  </channel>
</rss>

