<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: active / standby config in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905709#M457005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if i have it terminated on the same switch, will there be any case of spanning tree ? &lt;/P&gt;&lt;P&gt;if i have it on the same switch then yes it should be on same vlan but can i terminate this on a another switch? if this is the case then do i need an ip address for the second switch ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also is a statefull failure port definitely needed ? cant i use the failover port do the job of statefull failure also ? but if i do need another port for failover and statefull failover do i need to use a switch in between for lan failover ? - its just that too many switches &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Apr 2012 16:07:10 GMT</pubDate>
    <dc:creator>Network Pro</dc:creator>
    <dc:date>2012-04-16T16:07:10Z</dc:date>
    <item>
      <title>active / standby config</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905707#M456996</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;implementing active / standby configuration. i have two asa 5520 firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gi0/0 - inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&amp;nbsp;&amp;nbsp; 10.10.10.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; standby 10.10.10.254&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;gi0/1- outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&amp;nbsp;&amp;nbsp; 172.22.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; standby 172.22.1.254&lt;/P&gt;&lt;P&gt;gi0/2 - lan failover&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&amp;nbsp;&amp;nbsp; 192.168.100.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; standby 192.168.100.254&lt;/P&gt;&lt;P&gt;gi0/3 - state full failover&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&amp;nbsp;&amp;nbsp; 192.168.101.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; standby 192.168.101.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am doing this on a test environment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a silly question:&amp;nbsp; 1 port (inside interface) of the active asa will be connecting back to the switch, does the port on the 2nd asa need connecting on the same switch as well ?&amp;nbsp; (if i do this wont this be a single point of failure? )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and if i use the switch what will be its default gateway for hte inside network (10.10.10.1 or 10.10.10.254 ?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:54:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905707#M456996</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2019-03-11T22:54:19Z</dc:date>
    </item>
    <item>
      <title>active / standby config</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905708#M457000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, you do not need the inside port of the standby firewall to be on the same switch , but you will need it on the same VLAN.&lt;/P&gt;&lt;P&gt;If you will have both inside ports connected on the same switch , yes&amp;nbsp; it will be single point of failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 16:04:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905708#M457000</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2012-04-16T16:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: active / standby config</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905709#M457005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if i have it terminated on the same switch, will there be any case of spanning tree ? &lt;/P&gt;&lt;P&gt;if i have it on the same switch then yes it should be on same vlan but can i terminate this on a another switch? if this is the case then do i need an ip address for the second switch ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also is a statefull failure port definitely needed ? cant i use the failover port do the job of statefull failure also ? but if i do need another port for failover and statefull failover do i need to use a switch in between for lan failover ? - its just that too many switches &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 16:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905709#M457005</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2012-04-16T16:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: active / standby config</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905710#M457007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you will use the switch as a default gateway for the users/servers connected, yes you will need an Vlan interface on the second switch also , and use HSRP in order to offer more redundance - the case in which the first switch fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also another option is to use the firewall as the 'gateway' for the hosts. This depends on your setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can use only one port on the ASA pairs to do failover and statefull.&lt;/P&gt;&lt;P&gt;No you can use a direct cable between the pairs in order to have statefull/failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 16:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905710#M457007</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2012-04-16T16:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: active / standby config</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905711#M457011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; i am just doing this on a test environment - so i can use a single switch for the inside vlan and outside vlan just for testing purpose&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 16:28:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905711#M457011</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2012-04-16T16:28:07Z</dc:date>
    </item>
    <item>
      <title>active / standby config</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905712#M457012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok then.&lt;/P&gt;&lt;P&gt;You can use as the failover/statefull interface just one interface per ASA, and you can connected them directly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 16:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905712#M457012</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2012-04-16T16:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: active / standby config</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905713#M457015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; thanks used the same switch for inside and outside (just vlan off - vlan 1 for inside and vlan 10 for outside)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 11:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-config/m-p/1905713#M457015</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2012-04-17T11:10:32Z</dc:date>
    </item>
  </channel>
</rss>

