<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Standby ASA  Failover interface Mac address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294408#M345224</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When ASA is config as Active and standby then the failover interface never swap the IP address but other interfaces do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to know when standby ASA&amp;nbsp; becomes active will it swap the mac address with Failover&amp;nbsp; interface of Active ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh &lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:21:06 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2019-03-12T02:21:06Z</dc:date>
    <item>
      <title>Active Standby ASA  Failover interface Mac address</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294408#M345224</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When ASA is config as Active and standby then the failover interface never swap the IP address but other interfaces do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to know when standby ASA&amp;nbsp; becomes active will it swap the mac address with Failover&amp;nbsp; interface of Active ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:21:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294408#M345224</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T02:21:06Z</dc:date>
    </item>
    <item>
      <title>Active Standby ASA  Failover interface Mac address</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294409#M345225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The interface IP address and MAC address of the Active unit should always be the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the Failover happens the formed Standby device which now becomes Active should get the same IP address and MAC address as the previous Active unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So essentially there is no change in the ARP for connected devices hen the Active ASA changes and therefore there should be no outage in the connections and traffic forwarding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Aug 2013 18:58:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294409#M345225</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-04T18:58:46Z</dc:date>
    </item>
    <item>
      <title>Active Standby ASA  Failover interface Mac address</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294410#M345226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per CBT&amp;nbsp; videos it says Failover interface do not swap the IP address but all other interfaces swap the IP address?&lt;/P&gt;&lt;P&gt;Is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to confirm also failover interface mac address also get swapped or not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Aug 2013 19:17:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294410#M345226</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-08-04T19:17:06Z</dc:date>
    </item>
    <item>
      <title>Active Standby ASA  Failover interface Mac address</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294411#M345228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding they do as we specifically configure a primary and a standby IP address for the Failover link also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't really have any Failover pair handy with which I could confirm this but I would imagine that the Active unit always keeps the primary IP address configured with &lt;STRONG&gt;"failover"&lt;/STRONG&gt; command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover interrface ip &lt;INTERFACE name=""&gt; x.x.x.1 255.255.255.0 standby x.x.x.2&lt;/INTERFACE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Aug 2013 19:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294411#M345228</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-04T19:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Active Standby ASA  Failover interface Mac address</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294412#M345232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also can not test at home as i have only 1 asa with plus license nor i can at&amp;nbsp; work.&lt;/P&gt;&lt;P&gt;At work only if we have some scheduled change for ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets see if someone&amp;nbsp; in forum can confirm if this is true or not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Aug 2013 19:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294412#M345232</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-08-04T19:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Active Standby ASA  Failover interface Mac address</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294413#M345233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The old CCNP Firewall book does seem to mention that there is no chance for Failover LAN interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"The address swap occurs on every ASA interface except the LAN failover, which always remains unchanged"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Aug 2013 19:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294413#M345233</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-04T19:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Active Standby ASA  Failover interface Mac address</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294414#M345236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So does it mean that they never swap ips right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Aug 2013 19:35:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294414#M345236</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-08-04T19:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Active Standby ASA  Failover interface Mac address</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294415#M345240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems they stay the same. I was not aware of this though I guess it something you might miss as you are actually looking at the Data interfaces IP/MAC addresses if you are seeing trouble with a Failover pair.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I find very strange is that this isnt clearly stated in the Configuration Guide or Command Reference of the ASA. Or atleast I don't see a specific mention about the actual Failover link/interface but rather the mention of the Data interfaces which do change IP and MAC. (Or I have completely missed it)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yet its stated in some older documents&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a quote:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The failover link IP address and MAC address do not change at&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; failover. The active IP address for the failover link always stays with the&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; primary unit, while the standby IP address stays with the secondary unit. &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080aefd11.shtml#pri" rel="nofollow"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080aefd11.shtml#pri&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Aug 2013 20:02:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294415#M345240</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-04T20:02:38Z</dc:date>
    </item>
    <item>
      <title>Active Standby ASA  Failover interface Mac address</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294416#M345242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks that we both came to same conclusion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Aug 2013 21:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-interface-mac-address/m-p/2294416#M345242</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-08-04T21:02:34Z</dc:date>
    </item>
  </channel>
</rss>

