<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA failover - basic questions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-basic-questions/m-p/703258#M423348</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found an answer to my own questions when I tried it out!! Just wanted to share the same with all of you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Telnetting was possible to the inside interface standby IP. So, no need to have console access to the standby unit. It did not work earlier as the inside interface was connected to a different switch port. When changed, I was able to telnet to inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. I was also able to ping inside standby IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Not having a standby public IP for outside interface did not matter. It just showed up as 0.0.0.0 in show monitor-interface command. But when switched to active, it took the active public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. I think that management0/0 interface is a good option to use when in transparent firewall mode. Since, there are no IP's used for other interfaces, the firewall is managed using the management interface IP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;P&gt;Gautam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Sep 2006 06:03:41 GMT</pubDate>
    <dc:creator>gautamzone</dc:creator>
    <dc:date>2006-09-26T06:03:41Z</dc:date>
    <item>
      <title>ASA failover - basic questions</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-basic-questions/m-p/703257#M423346</link>
      <description>&lt;P&gt;Hi friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wanted to know a few things. The platform is confined to ASA 5540 and version 7.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.Can I not telnet into one of standby's interface Ip's? This is just to check if it has the same configuration as the active one? I just want to escape the server room air-conditing and consoling to the standby unit to check config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Is pinging not possible to any of the standby IP's of Standby unit? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. If outside (public IP) interface of Active unit has no standby IP (to conserve address space), is it ok? What are the effects of not having a standby IP? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. What is the role of management0/0 interface in failover configuration? Is management interface really necessary for a failover configuration? What exactly is the purpose of it? Can i do a successful failover with a shutted management interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;Gautam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-basic-questions/m-p/703257#M423346</guid>
      <dc:creator>gautamzone</dc:creator>
      <dc:date>2020-02-21T09:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover - basic questions</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-basic-questions/m-p/703258#M423348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found an answer to my own questions when I tried it out!! Just wanted to share the same with all of you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Telnetting was possible to the inside interface standby IP. So, no need to have console access to the standby unit. It did not work earlier as the inside interface was connected to a different switch port. When changed, I was able to telnet to inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. I was also able to ping inside standby IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Not having a standby public IP for outside interface did not matter. It just showed up as 0.0.0.0 in show monitor-interface command. But when switched to active, it took the active public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. I think that management0/0 interface is a good option to use when in transparent firewall mode. Since, there are no IP's used for other interfaces, the firewall is managed using the management interface IP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;P&gt;Gautam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Sep 2006 06:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-basic-questions/m-p/703258#M423348</guid>
      <dc:creator>gautamzone</dc:creator>
      <dc:date>2006-09-26T06:03:41Z</dc:date>
    </item>
  </channel>
</rss>

