<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Firewall HA Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-firewall-ha-configuration/m-p/1700080#M417240</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try configure failover as per diagram, but it didn't work. Below is how i configure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Primary:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g0/0&lt;/P&gt;&lt;P&gt; ip address 192.168.50.5 255.255.255.0 standby 192.168.50.6&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; nameif public&lt;/P&gt;&lt;P&gt; no shut&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g0/1&lt;/P&gt;&lt;P&gt; ip address 172.16.0.5 255.255.0.0 standby 172.16.0.6&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; no shut&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.80.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt; no shut&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover g0/3&lt;/P&gt;&lt;P&gt;failover key cisco&lt;/P&gt;&lt;P&gt;failover interface ip failover 192.168.100.1 255.255.255.0 standby 192.168.100.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Secondary:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;int g0/0&lt;BR /&gt; ip address 192.168.50.6 255.255.255.0&lt;BR /&gt; security-level 0&lt;BR /&gt; nameif public&lt;BR /&gt; no shut&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g0/1&lt;BR /&gt; ip address 172.16.0.6 255.255.0.0&lt;BR /&gt; security-level 100&lt;BR /&gt; nameif inside&lt;BR /&gt; no shut&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.80.2 255.255.255.0 &lt;BR /&gt; management-only&lt;BR /&gt; no shut&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface failover g0/3&lt;BR /&gt;failover key cisco&lt;BR /&gt;failover interface ip failover 192.168.100.1 255.255.255.0 standby 192.168.100.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my configuration correct?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:18:53 GMT</pubDate>
    <dc:creator>VincentLong</dc:creator>
    <dc:date>2020-02-21T12:18:53Z</dc:date>
    <item>
      <title>ASA Firewall HA Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-ha-configuration/m-p/1700080#M417240</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try configure failover as per diagram, but it didn't work. Below is how i configure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Primary:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g0/0&lt;/P&gt;&lt;P&gt; ip address 192.168.50.5 255.255.255.0 standby 192.168.50.6&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; nameif public&lt;/P&gt;&lt;P&gt; no shut&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g0/1&lt;/P&gt;&lt;P&gt; ip address 172.16.0.5 255.255.0.0 standby 172.16.0.6&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; no shut&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.80.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt; no shut&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover g0/3&lt;/P&gt;&lt;P&gt;failover key cisco&lt;/P&gt;&lt;P&gt;failover interface ip failover 192.168.100.1 255.255.255.0 standby 192.168.100.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Secondary:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;int g0/0&lt;BR /&gt; ip address 192.168.50.6 255.255.255.0&lt;BR /&gt; security-level 0&lt;BR /&gt; nameif public&lt;BR /&gt; no shut&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g0/1&lt;BR /&gt; ip address 172.16.0.6 255.255.0.0&lt;BR /&gt; security-level 100&lt;BR /&gt; nameif inside&lt;BR /&gt; no shut&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.80.2 255.255.255.0 &lt;BR /&gt; management-only&lt;BR /&gt; no shut&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface failover g0/3&lt;BR /&gt;failover key cisco&lt;BR /&gt;failover interface ip failover 192.168.100.1 255.255.255.0 standby 192.168.100.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my configuration correct?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:18:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-ha-configuration/m-p/1700080#M417240</guid>
      <dc:creator>VincentLong</dc:creator>
      <dc:date>2020-02-21T12:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firewall HA Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-ha-configuration/m-p/1700081#M417242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vincent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The failover configuration on the primary is fine. But on the Secondary unit you just need the following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g0/0&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g0/1&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface failover g0/3&lt;BR /&gt;failover key cisco&lt;BR /&gt;failover interface ip failover 192.168.100.1 255.255.255.0 standby 192.168.100.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need not assign Ip addresses to the interfaces on the secondary ASA. Once the failover is on the config is pushed by the Active unit to the standby unit. So once the primary ASA becomes active it will push the standby IP addresses to the interfaces of the standby unit. Do note that is it recommended that the 'failover' command should be issued after entering all the failover configuration . You can check the status of the failover by ' show failover' command. Enabling the logs will also help you isolate the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regard,&lt;/P&gt;&lt;P&gt;Som&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: Please mark the question resolved if it has been answered. Do rate helpful posts. Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 12:21:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-ha-configuration/m-p/1700081#M417242</guid>
      <dc:creator>Somanna M.P</dc:creator>
      <dc:date>2011-04-11T12:21:23Z</dc:date>
    </item>
  </channel>
</rss>

