<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic In high availability Active-Active or Active-Passive is VPN supp in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202164#M360310</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; it is actually active/active...since 1 device is active for a certain group of contexts, and the other device is active for the other group of contexts.&lt;/P&gt;&lt;P&gt;its like instead of having 10 contexts passing traffic on 1 device, you have 5 contexts passing traffic on ASA1 and the other 5 on ASA2, so it is achieveing reasonable load sharing so you not overwhelm 1 device with all that amount of traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and you are correct, it is still the same concept as it was in version 7.x &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Mar 2013 13:02:28 GMT</pubDate>
    <dc:creator>oamarneh</dc:creator>
    <dc:date>2013-03-13T13:02:28Z</dc:date>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supported</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202156#M360299</link>
      <description>&lt;P&gt;My question is as simple as the title!&lt;BR /&gt;Let me know.&lt;BR /&gt;Regards! &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:13:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202156#M360299</guid>
      <dc:creator>Lasandro Lopez</dc:creator>
      <dc:date>2019-03-12T01:13:32Z</dc:date>
    </item>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supp</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202157#M360300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; with active-standby setup, yes ALL vpn types are supported. however, with Active-Active, you must have your ASA in multiple-context mode, VPN is not supported with multi context mode, however, starting ASA version 9.0, only Site to Site VPN is supported with multi-context mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 10:32:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202157#M360300</guid>
      <dc:creator>oamarneh</dc:creator>
      <dc:date>2013-03-13T10:32:33Z</dc:date>
    </item>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supp</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202158#M360301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As of ASA 9.0 you can have static l2l VPN in multicontext-mode. &lt;/P&gt;&lt;P&gt;In single context we've been supporting different VPNs for years. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 10:32:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202158#M360301</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2013-03-13T10:32:43Z</dc:date>
    </item>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supp</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202159#M360302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;does it mean that you still have separate HSRP group for l2l vpn in Active/Active?&amp;nbsp; In other words, traffics from the same source going to the same destination will traverse only one ASA and that the other ASA will serve as standby?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 11:39:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202159#M360302</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-03-13T11:39:31Z</dc:date>
    </item>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supp</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202160#M360303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; i am not sure i understood your question properly David.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with active active failover, the ASA will be configured with more than one context (usually), and failover status will be according to the failover-group, so certain contexts will be active on ASA1 standby on ASA2, while the other contexts will be active on ASA2 and standby on ASA1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so at the end, each context is considered a firewall on its own, non related to other contexts.&lt;/P&gt;&lt;P&gt;so starting version 9.0.1, you can configure static L2L tunnels on each context as needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i hope that this answers your question, if not, please provide more details &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Othman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 12:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202160#M360303</guid>
      <dc:creator>oamarneh</dc:creator>
      <dc:date>2013-03-13T12:20:10Z</dc:date>
    </item>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supp</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202161#M360304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in Cisco ASA active/active firewalls, let say you have two network 192.168.1.0/24 and 191.268.2.0/24 behind the firewall trying to get to 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Active/Active in Cisco ASA means that 192.168.1.0/24 will go through ASA1 and 192.168.2.0/24 will go through ASA2 to get to 1.1.1.1.&amp;nbsp; It is like multiple HSRP group where ASA1 will be active for group 1 and ASA2 is standby for group 1 while ASA2 is active for group2 and ASA1 is standby for group2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is different than Active/Active than other vendors.&amp;nbsp; When Active/Active, you can have the same 192.168.1.0/24 going across both firewall for the same destination 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's what I mean.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 12:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202161#M360304</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-03-13T12:29:15Z</dc:date>
    </item>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supp</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202162#M360306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; to simplify it, each context will act as a separate firewall, and for a certain failover group, the context will be active on ASA1 and standby on ASA2, so traffic for the subnets behind that context will pass through the active firewall, not the standby.&lt;/P&gt;&lt;P&gt;traffic will not pass through both firewalls for the same context, its not actuall loadbalancing here, but more of load distribution between the 2 ASA units.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 12:37:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202162#M360306</guid>
      <dc:creator>oamarneh</dc:creator>
      <dc:date>2013-03-13T12:37:11Z</dc:date>
    </item>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supp</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202163#M360308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the clarification.&amp;nbsp; That's what I am afraid of.&amp;nbsp; Cisco interpretation of "Active/Active" is &lt;EM&gt;not&lt;/EM&gt; the same as other vendors. IMHO, it is mis-leasding.&amp;nbsp; Basically, it has not changed since version 7.x &lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is all in the &lt;EM&gt;fine print&lt;/EM&gt;, not those big words &lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 12:41:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202163#M360308</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-03-13T12:41:51Z</dc:date>
    </item>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supp</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202164#M360310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; it is actually active/active...since 1 device is active for a certain group of contexts, and the other device is active for the other group of contexts.&lt;/P&gt;&lt;P&gt;its like instead of having 10 contexts passing traffic on 1 device, you have 5 contexts passing traffic on ASA1 and the other 5 on ASA2, so it is achieveing reasonable load sharing so you not overwhelm 1 device with all that amount of traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and you are correct, it is still the same concept as it was in version 7.x &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 13:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202164#M360310</guid>
      <dc:creator>oamarneh</dc:creator>
      <dc:date>2013-03-13T13:02:28Z</dc:date>
    </item>
    <item>
      <title>In high availability Active-Active or Active-Passive is VPN supp</title>
      <link>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202165#M360311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it is active/active &lt;EM&gt;per&lt;/EM&gt; virtual context but certain &lt;EM&gt;not&lt;/EM&gt; active/active within a particular context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will give you an example.&amp;nbsp; let say you have 192.168.1.0/24 and 192.168.2.0/24 and for the sake of the argument, you have 100Mbps on both ASA1 and ASA2 and that the network 192.168.1.0/24 and 192.168.2.0/24 is 1Gbps link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now let say that 192.168.1.0/24 needs to access 1.1.1.1 and ASA1 is active for .1.0/24 and ASA2 and standby for .1.0/24 and vice versa for .2.0/24.&amp;nbsp; let assume that there are very little traffics on network 192.168.2.0/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;based on cisco definition of active/active, you will max out @100Mbps on 192.168.1.0/24 getting to 1.1.1.1 on ASA1 while ASA2 is just sitting idle.&amp;nbsp; For a true active/active, I should get 200Mbps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that's why I said "Active/Active" in Cisco is kinda mis-leading... That's why you need to read the &lt;EM&gt;&lt;STRONG&gt;fine print&lt;/STRONG&gt;&lt;/EM&gt; &lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 13:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-high-availability-active-active-or-active-passive-is-vpn/m-p/2202165#M360311</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-03-13T13:39:16Z</dc:date>
    </item>
  </channel>
</rss>

