<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5540 standby ip in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5540-standby-ip/m-p/1997523#M401155</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) Looking at the network mask used in the interface it seems that the standby IP address is configured wrong. Also, there is not supposed to be any configurations related to the standby IP address. I mean no NAT configurations or access-list statements as its just there for the Failover to work. (To my understanding)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) What you should do is configure another IP from the same network range as the primary IP. When you change the standby IP address you naturally only configure it on the active device as the standby device automatically receives the configuration change from the primary device (provided that the actual failover is working properly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) The IP ending in .120 cannot be used as its not from the same network range as .100 (when you are using a mask of /29) When you have a correct IP address from same network configured on the standby ASA you should be able to ping it and also see it on the "show arp" command on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Aug 2012 07:56:46 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-08-07T07:56:46Z</dc:date>
    <item>
      <title>ASA5540 standby ip</title>
      <link>https://community.cisco.com/t5/network-security/asa5540-standby-ip/m-p/1997522#M401152</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this 2x ASA5540 firewall and notice the it is configured with a standby ip. The firewall is run in Active/Passive mode.&lt;/P&gt;&lt;P&gt;However, the standby ip of this firewall is not point to the seconday firewall and vice versa for the primary firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ASA5540_Pri&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;interface GigabitEthernet0/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;nameif dmz_pri&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;security-level 50&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;ip address x.x.x.100 255.255.255.248 standby x.x.x.120 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; "&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;1) May i know how is this configuration valid in the first place? I have checked through the configuration. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;None of the configuration is related to this ip address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; "&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;2) Can we remove this standby ip address on both the firewall and correct to the correct primary and seconadary ip address in both firewall?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; "&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; "&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;3) We tried to use this ip address but cannot be used ? Any idea is it related to the configuration of the standby ip address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Do note that the ping to this ip address x.x.x.120 is unreachable.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;KH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5540-standby-ip/m-p/1997522#M401152</guid>
      <dc:creator>kian_hong2000</dc:creator>
      <dc:date>2019-03-11T23:39:02Z</dc:date>
    </item>
    <item>
      <title>ASA5540 standby ip</title>
      <link>https://community.cisco.com/t5/network-security/asa5540-standby-ip/m-p/1997523#M401155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) Looking at the network mask used in the interface it seems that the standby IP address is configured wrong. Also, there is not supposed to be any configurations related to the standby IP address. I mean no NAT configurations or access-list statements as its just there for the Failover to work. (To my understanding)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) What you should do is configure another IP from the same network range as the primary IP. When you change the standby IP address you naturally only configure it on the active device as the standby device automatically receives the configuration change from the primary device (provided that the actual failover is working properly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) The IP ending in .120 cannot be used as its not from the same network range as .100 (when you are using a mask of /29) When you have a correct IP address from same network configured on the standby ASA you should be able to ping it and also see it on the "show arp" command on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Aug 2012 07:56:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5540-standby-ip/m-p/1997523#M401155</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-08-07T07:56:46Z</dc:date>
    </item>
  </channel>
</rss>

