<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA active/standby configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968083#M434814</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have a LAN-based failover setup between two 5510s. The failover link is a crossover cable. In the current setup, if I unplug the crossover cable both units become active. From what I understood from Cisco documentation, each unit should mark the failover interface as down and there shouldn't be any failover. That's exactly how I want this setup to work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Can someone please help me clarify/fix this?&lt;/P&gt;&lt;P&gt;2) Will a second failover link fix my problem?&lt;/P&gt;&lt;P&gt;3) How can I configure a second failover link? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your time!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ranil&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:15:41 GMT</pubDate>
    <dc:creator>Ranil Herath</dc:creator>
    <dc:date>2019-03-11T23:15:41Z</dc:date>
    <item>
      <title>ASA active/standby configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968083#M434814</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have a LAN-based failover setup between two 5510s. The failover link is a crossover cable. In the current setup, if I unplug the crossover cable both units become active. From what I understood from Cisco documentation, each unit should mark the failover interface as down and there shouldn't be any failover. That's exactly how I want this setup to work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Can someone please help me clarify/fix this?&lt;/P&gt;&lt;P&gt;2) Will a second failover link fix my problem?&lt;/P&gt;&lt;P&gt;3) How can I configure a second failover link? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your time!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ranil&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968083#M434814</guid>
      <dc:creator>Ranil Herath</dc:creator>
      <dc:date>2019-03-11T23:15:41Z</dc:date>
    </item>
    <item>
      <title>ASA active/standby configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968084#M434815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you unplug the failover cable, both units will definitely become active because they can't communicate with each other, hence both resume the active role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is recommended to connect the failover link to switch instead of using crossover cable because it is more difficult to troubleshoot if you are using crossover cable when it fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure redundant interface to have a standby physical link for your failover link.&lt;/P&gt;&lt;P&gt;Here is the configuration guide for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/interface_start.html#wp1062296"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/interface_start.html#wp1062296&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 14:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968084#M434815</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-05T14:58:56Z</dc:date>
    </item>
    <item>
      <title>ASA active/standby configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968085#M434816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply Jennifer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was reffering to the following document:&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1091405"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1091405&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp1091405table1091399" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); width: 80%; "&gt;&lt;TBODY&gt;&lt;TR align="left" valign="bottom"&gt;&lt;TH scope="col" style="font-size: 14px;"&gt;&lt;P style="color: #336666; margin: 0em; text-indent: 0em;"&gt;Failure Event&lt;/P&gt;&lt;/TH&gt;&lt;TH scope="col" style="font-size: 14px;"&gt;&lt;A name="wp1091417"&gt;&lt;/A&gt;&lt;P style="color: #336666; margin: 0em; text-indent: 0em;"&gt;Policy&lt;/P&gt;&lt;/TH&gt;&lt;TH scope="col" style="font-size: 14px;"&gt;&lt;A name="wp1091419"&gt;&lt;/A&gt;&lt;P style="color: #336666; margin: 0em; text-indent: 0em;"&gt;Active Action&lt;/P&gt;&lt;/TH&gt;&lt;TH scope="col" style="font-size: 14px;"&gt;&lt;A name="wp1091421"&gt;&lt;/A&gt;&lt;P style="color: #336666; margin: 0em; text-indent: 0em;"&gt;Standby Action&lt;/P&gt;&lt;/TH&gt;&lt;TH scope="col" style="font-size: 14px;"&gt;&lt;A name="wp1091423"&gt;&lt;/A&gt;&lt;P style="color: #336666; margin: 0em; text-indent: 0em;"&gt;Notes&lt;/P&gt;&lt;/TH&gt; &lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;A name="wp1091456"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;Failover link failed during operation&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1091458"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;No failover&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1091460"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;Mark failover interface as failed&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1091462"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;Mark failover interface as failed&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1091464"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;You should restore the failover link as soon as possible because the unit cannot fail over to the standby unit while the failover link is down.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;A name="wp1091476"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;Stateful Failover link failed&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1091478"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;No failover&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1091480"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;No action&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1091482"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;No action&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1091484"&gt;&lt;/A&gt;&lt;P style="font-size: 12px; margin: 1px 0em 6px; text-indent: 0em;"&gt;State information becomes out of date, and sessions are terminated if a failover occurs.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #336666; font-size: 14px; font-family: Arial, Helvetica, sans-serif; "&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I should rephrase question 2) If I have two seperate links for Failover and Stateful failover, will that fix my problem?&lt;/P&gt;&lt;P&gt;How can I configure seperate Failover and Stateful failover links? If I understand correctly, they are more than just redundant links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry I didn't accurately phrase my original post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 15:43:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968085#M434816</guid>
      <dc:creator>Ranil Herath</dc:creator>
      <dc:date>2012-06-05T15:43:33Z</dc:date>
    </item>
    <item>
      <title>ASA active/standby configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968086#M434817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, it won't fix your problem because the 2 are actually passing different types of information.&lt;/P&gt;&lt;P&gt;The failover link is to ensure that all the interfaces are up and there is no failure on either of the ASA.&lt;/P&gt;&lt;P&gt;The stateful failover link is to pass the firewall connection table, xlate table, VPN session, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if the failover link fails, then you are at the same stage as when you use just 1 interface for both failover and stateful failover link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like to separate the 2 anyway, you can configure it, just assign different interface and ip address for each failover links:&lt;/P&gt;&lt;P&gt;eg:&lt;/P&gt;&lt;P&gt;failover link &lt;STATEFUL-LINK-INT-NAME&gt; eth2&lt;/STATEFUL-LINK-INT-NAME&gt;&lt;/P&gt;&lt;P&gt;failover lan interface &lt;FAILOVER-LINK-INT-NAME&gt; eth3&lt;/FAILOVER-LINK-INT-NAME&gt;&lt;/P&gt;&lt;P&gt;failover interface ip &lt;STATEFUL-LINK-INT-NAME&gt; &lt;IPADDRESS&gt; &lt;MASK&gt; standby &lt;STANDBYIP&gt;&lt;/STANDBYIP&gt;&lt;/MASK&gt;&lt;/IPADDRESS&gt;&lt;/STATEFUL-LINK-INT-NAME&gt;&lt;/P&gt;&lt;P&gt;failover interface ip &lt;FAILOVER-LINK-INT-NAME&gt; &lt;IPADDRESS&gt; &lt;MASK&gt; standby &lt;STANDBYIP&gt;&lt;/STANDBYIP&gt;&lt;/MASK&gt;&lt;/IPADDRESS&gt;&lt;/FAILOVER-LINK-INT-NAME&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 02:55:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968086#M434817</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-06T02:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA active/standby configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968087#M434818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Thank you Jennifer. I configured a Stateful link using the commands you mentioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Thought you might be interested to know that everything is now working as I expected! The ASAs do not failover when I unplug,&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;1) The Failover link&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;2) The Stateful failover link&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;3) Both Failover and Stateful failover links&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I had to reconfigure the Active and Standby IPs of the INSIDE and OUTSIDE interfaces. Now I can see the standby IPs assigned on the Standby ASA. Whereas earlier there were no IPs assigned to the INSIDE and OUTSIDE interfaces on the Standby ASA. This might have been a config replication problem over the Failover link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;For anyone interested, the failover scenarios in&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1091405" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681; text-decoration: none;"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1091405&lt;/A&gt;should work absolutely fine in an Active/Standby ASA HA config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 12:15:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968087#M434818</guid>
      <dc:creator>Ranil Herath</dc:creator>
      <dc:date>2012-06-06T12:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA active/standby configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968088#M434819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, thanks for the update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 12:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-configuration/m-p/1968088#M434819</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-06T12:51:40Z</dc:date>
    </item>
  </channel>
</rss>

