<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046345#M396287</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; thanks i will try this&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Nov 2012 09:18:43 GMT</pubDate>
    <dc:creator>Network Pro</dc:creator>
    <dc:date>2012-11-06T09:18:43Z</dc:date>
    <item>
      <title>Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046339#M396281</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am trying to setup a failover pair on Cisco asa 5520 - need a statefull failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do i need two ports dedicated to obtain the above - one for LAN based failover and one for statefull failver ? also do i need a switch in between to connect them ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you please help me with a config ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046339#M396281</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2019-03-12T00:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046340#M396282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can combine both funtions (LAN-link and stateful link) on one ethernet-link. That is quite common and works well on a 5520. A crossover-cable is supported on the ASA for that functionality.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All you need is in the config-guide:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_active_standby.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_active_standby.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Nov 2012 16:36:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046340#M396282</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-11-01T16:36:28Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046341#M396283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Karsten. Just wondering is there any drawbacks by using just 1 link ? because we this is a vpn termination unit and essentially needs to be up 24/7&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Nov 2012 08:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046341#M396283</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2012-11-02T08:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046342#M396284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the 5520 there is no real drawback when you use one of the Gig-links for the FO-traffic (the 5510 supports a 100 MBit/s link for FO, but on the ASA you shouldn't use the m0/0-interface). Only on the high-end-systems it is imnportant to use a link that is fast enough to send all the state-changes to the standby-unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To increase the availability of this important link you could use the redundant-interface feature or even a port-channel for FO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Nov 2012 08:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046342#M396284</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-11-02T08:56:08Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046343#M396285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; so does the failover link should be differennt from the statefull link (just for statefull info to pass through?)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Nov 2012 11:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046343#M396285</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2012-11-02T11:19:25Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046344#M396286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;so does the failover link should be differennt from the statefull link (just for statefull info to pass through?)&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no, the 5520 has no problems to provide both functions through one physical link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Nov 2012 12:00:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046344#M396286</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-11-02T12:00:23Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046345#M396287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; thanks i will try this&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2012 09:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046345#M396287</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2012-11-06T09:18:43Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046346#M396288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just a quick question. Do i need to use a seperate switch for the cables coming from the outside interface and inside interface (i mean a cable will be coming out of each firewall for hte outside interface and inside interface that will go into a switch, isnt it ? so do i need to use two seperate switches - one for inside pair and other for outside pair? or can i use hte same switch and vlan off. also i have dmz setup so i need a another switch for this dmz as well ?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 14:31:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046346#M396288</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2012-12-12T14:31:54Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046347#M396289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Technically, that can be done. Just use different VLANs for inside, outside and DMZ. But it's not a best practice to use the same switch for inside and outside. If your switch has a bug or misconfiguration, it is possible that you directly connect you inside network with the internet. The firewall would be bypassed in that case. So better use your existing switch for inside and buy an 8-port-switch or something like that for outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 14:40:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046347#M396289</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-12-12T14:40:29Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046348#M396290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for hte quick reply karsten but for dmz do i need another one as well ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 14:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046348#M396290</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2012-12-12T14:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046349#M396291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you are paranoid, yes! &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But many times that interface is shared on the outside- or inside-switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 15:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046349#M396291</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-12-12T15:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046350#M396292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Karsten &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 15:41:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-failover/m-p/2046350#M396292</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2012-12-12T15:41:06Z</dc:date>
    </item>
  </channel>
</rss>

