<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Failover: Maintain management IPs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926089#M437061</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to work out if it's possible on ASAs to have the devices failover, but have the management IP not failover. So as an example: -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PRE FAILOVER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;Interface&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;ASA 1&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;ASA2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Inside&lt;/TD&gt;&lt;TD&gt;192.168.1.1/24&lt;/TD&gt;&lt;TD&gt;192.168.1.2/24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Outside&lt;/TD&gt;&lt;TD&gt;192.168.2.1/24&lt;/TD&gt;&lt;TD&gt;192.168.2.2/24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Management0/0&lt;/TD&gt;&lt;TD&gt;10.1.1.1/24&lt;/TD&gt;&lt;TD&gt;10.2.1.1/24&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;POST FAILOVER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;Interface&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;ASA 1&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;ASA 2&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Inside&lt;/TD&gt;&lt;TD&gt;192.168.1.2/24&lt;/TD&gt;&lt;TD&gt;192.168.1.1/24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Outside&lt;/TD&gt;&lt;TD&gt;192.168.2.2/24&lt;/TD&gt;&lt;TD&gt;192.168.2.1/24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Management0/0&lt;/TD&gt;&lt;TD&gt;10.1.1.1/24&lt;/TD&gt;&lt;TD&gt;10.2.1.1/24&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"&gt;﻿&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to do failover this way? I've tried disabling Man0/0 as a monitored-interface, but it makes no difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:06:34 GMT</pubDate>
    <dc:creator>showlette</dc:creator>
    <dc:date>2019-03-11T23:06:34Z</dc:date>
    <item>
      <title>ASA Failover: Maintain management IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926089#M437061</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to work out if it's possible on ASAs to have the devices failover, but have the management IP not failover. So as an example: -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PRE FAILOVER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;Interface&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;ASA 1&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;ASA2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Inside&lt;/TD&gt;&lt;TD&gt;192.168.1.1/24&lt;/TD&gt;&lt;TD&gt;192.168.1.2/24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Outside&lt;/TD&gt;&lt;TD&gt;192.168.2.1/24&lt;/TD&gt;&lt;TD&gt;192.168.2.2/24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Management0/0&lt;/TD&gt;&lt;TD&gt;10.1.1.1/24&lt;/TD&gt;&lt;TD&gt;10.2.1.1/24&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;POST FAILOVER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;Interface&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;ASA 1&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;ASA 2&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Inside&lt;/TD&gt;&lt;TD&gt;192.168.1.2/24&lt;/TD&gt;&lt;TD&gt;192.168.1.1/24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Outside&lt;/TD&gt;&lt;TD&gt;192.168.2.2/24&lt;/TD&gt;&lt;TD&gt;192.168.2.1/24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Management0/0&lt;/TD&gt;&lt;TD&gt;10.1.1.1/24&lt;/TD&gt;&lt;TD&gt;10.2.1.1/24&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"&gt;﻿&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to do failover this way? I've tried disabling Man0/0 as a monitored-interface, but it makes no difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926089#M437061</guid>
      <dc:creator>showlette</dc:creator>
      <dc:date>2019-03-11T23:06:34Z</dc:date>
    </item>
    <item>
      <title>ASA Failover: Maintain management IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926090#M437062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Staurt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's not possible, because whatever IP you give it to your management interface, it would be overwriiten with the one that you have on Primary firewalls when the replication happens. So the setup that you are looking for might not be possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 11:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926090#M437062</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-14T11:32:37Z</dc:date>
    </item>
    <item>
      <title>ASA Failover: Maintain management IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926091#M437063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had expected this to be the case unfortunately. Seems like a bit of an oversight really, as management access that you can't have unless a device is in a certain mode, and may change, isn't much like management access to me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 11:57:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926091#M437063</guid>
      <dc:creator>showlette</dc:creator>
      <dc:date>2012-05-14T11:57:27Z</dc:date>
    </item>
    <item>
      <title>ASA Failover: Maintain management IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926092#M437064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No you can access the management interface of the standby firewall, even if it is in standby state. I am sorry but Ia m not really sure about your requirement and would suggest if you can let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 11:59:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926092#M437064</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-14T11:59:31Z</dc:date>
    </item>
    <item>
      <title>ASA Failover: Maintain management IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926093#M437065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We would like the ASAs to be monitored and reachable separately. If the management IP switches over, that negates monitoring of the IP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideally we would like the firewall management IPs to be in completely different subnets, which looks impossible with the way they currently work. An example is exactly like my first post.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 12:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-maintain-management-ips/m-p/1926093#M437065</guid>
      <dc:creator>showlette</dc:creator>
      <dc:date>2012-05-14T12:04:21Z</dc:date>
    </item>
  </channel>
</rss>

