<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA ACTIVE/PASSIVE Failover with OSPF Peering - Best Practices in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001364#M440690</link>
    <description>&lt;P&gt;I've been searching the web trying to find some answers regarding best practices when it comes to ASA Active/passive failover with OSPF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have pairs of 5520s and 5540s connected to pairs of nexus 7ks and 6500 switches.&amp;nbsp; The ASAs plug into switchports on the same VLAN, and peer with OSPF to the SVI on the switches.&amp;nbsp; This is working fine, but the problem I am running into is the 2 switches are peering with OSPF across the layer 2 link.&amp;nbsp; We prefer the switches to only peer across a seperate L3 link we have between the switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How would one go about preventing the switches from peering across the L2 link, but the active ASA continue to peer with both switches?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have links to any best practices documents that go into further detail of deploying ASA active/passive failover with OSPF?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:20:51 GMT</pubDate>
    <dc:creator>Andrew4728</dc:creator>
    <dc:date>2019-03-11T23:20:51Z</dc:date>
    <item>
      <title>Cisco ASA ACTIVE/PASSIVE Failover with OSPF Peering - Best Practices</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001364#M440690</link>
      <description>&lt;P&gt;I've been searching the web trying to find some answers regarding best practices when it comes to ASA Active/passive failover with OSPF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have pairs of 5520s and 5540s connected to pairs of nexus 7ks and 6500 switches.&amp;nbsp; The ASAs plug into switchports on the same VLAN, and peer with OSPF to the SVI on the switches.&amp;nbsp; This is working fine, but the problem I am running into is the 2 switches are peering with OSPF across the layer 2 link.&amp;nbsp; We prefer the switches to only peer across a seperate L3 link we have between the switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How would one go about preventing the switches from peering across the L2 link, but the active ASA continue to peer with both switches?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have links to any best practices documents that go into further detail of deploying ASA active/passive failover with OSPF?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001364#M440690</guid>
      <dc:creator>Andrew4728</dc:creator>
      <dc:date>2019-03-11T23:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACTIVE/PASSIVE Failover with OSPF Peering - Best P</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001365#M440691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nobody?  How do you have your active/standby asas setup with ospf?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2012 00:21:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001365#M440691</guid>
      <dc:creator>Andrew4728</dc:creator>
      <dc:date>2012-06-20T00:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACTIVE/PASSIVE Failover with OSPF Peering - Best P</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001366#M440692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since the active Asa in a cluster keeps the same ip address and Mac address regardless of which physical is active,  i think the switchports to both active and standby have to be l2 adjacent.   I usually recommend a wan edge  switching fabric and offload this from the core so you can bridge the vlan there between Asa clusters, and keep your core l3 peered to the Asa.  Hth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2012 03:26:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001366#M440692</guid>
      <dc:creator>Josh Sprang</dc:creator>
      <dc:date>2012-06-20T03:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACTIVE/PASSIVE Failover with OSPF Peering - Best P</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001367#M440693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We do have wan switches, but arnt running routing protocols on outside..  We have ospf between the LAN switches and the asa to dynamically advertise routes to remote vpn sites..  The problem im trying to find a solution to is our lan switches peering with each other through the svis over the layer 2 link...  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?  Been mulching through every cisco doc i can find and havent found an answer yet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks guys!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2012 04:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001367#M440693</guid>
      <dc:creator>Andrew4728</dc:creator>
      <dc:date>2012-06-20T04:43:52Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA ACTIVE/PASSIVE Failover with OSPF Peering - Best Pract</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001368#M440694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have run into this same problem.&amp;nbsp; A suggestion I had from a colleague was to configure the SVI OSPF network type to non-broadcast, and then configure static neighbours with the firewall from the switches.&amp;nbsp; I was going to give this a try but if you are willing to be the guinea pig then I'll happily let you road-test it for me!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 07:06:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-active-passive-failover-with-ospf-peering-best/m-p/2001368#M440694</guid>
      <dc:creator>tombell01</dc:creator>
      <dc:date>2012-06-27T07:06:13Z</dc:date>
    </item>
  </channel>
</rss>

