<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA - New HA Design - Limitations in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-new-ha-design-limitations/m-p/2015280#M416686</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mikull,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For a good desing ( Check the status of all the network interfaces) you do need it as failover is based on the exchange of hello packets between both the primary and secondary boxes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any other question.. Let me know.. Just remember to rate all of my answers.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Sep 2012 22:24:07 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-09-12T22:24:07Z</dc:date>
    <item>
      <title>ASA - New HA Design - Limitations</title>
      <link>https://community.cisco.com/t5/network-security/asa-new-ha-design-limitations/m-p/2015278#M416684</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;hey folks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;I have these two brand spanking 5540's which would be configured in a HA design(Active/Standby)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;The only bugger is this client has no spare IP's which can be used on the inside nor the outside.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;Yes, all I have been given is two IP's(inside and outside)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;I plan to use gig4 for command replication and monitoring&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;Yes, the design is such that these two new ASA's would be a second layer of security.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;Now, is it absolutely necessary to have a secondary IP on the inside interface for the failover to occur or just a standby IP on the dedicated management interface is enough for the failover to happen?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;Also, can someone let me know where ASA support interface tracking and punishing the active or standby device to give-up it's active state?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:44:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-new-ha-design-limitations/m-p/2015278#M416684</guid>
      <dc:creator>mikull.kiznozki</dc:creator>
      <dc:date>2020-02-21T12:44:11Z</dc:date>
    </item>
    <item>
      <title>ASA - New HA Design - Limitations</title>
      <link>https://community.cisco.com/t5/network-security/asa-new-ha-design-limitations/m-p/2015279#M416685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i mean standby ip and not a secondary ip &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2012 05:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-new-ha-design-limitations/m-p/2015279#M416685</guid>
      <dc:creator>mikull.kiznozki</dc:creator>
      <dc:date>2012-09-11T05:43:53Z</dc:date>
    </item>
    <item>
      <title>ASA - New HA Design - Limitations</title>
      <link>https://community.cisco.com/t5/network-security/asa-new-ha-design-limitations/m-p/2015280#M416686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mikull,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For a good desing ( Check the status of all the network interfaces) you do need it as failover is based on the exchange of hello packets between both the primary and secondary boxes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any other question.. Let me know.. Just remember to rate all of my answers.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 22:24:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-new-ha-design-limitations/m-p/2015280#M416686</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-09-12T22:24:07Z</dc:date>
    </item>
  </channel>
</rss>

