<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to trigger failover in a multi context ASA firewall environm in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878399#M492637</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;Thanks for the info.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Say I want to configure the standby to take over if the either the e0/0 trunk uplink to the WAN or the e0/1 trunk downlink to the LAN get disconnected (accidentally unplugged) on the primary... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would confugrure that in the system context, right?&amp;nbsp; If so, what would I add to the current primary system configuration to make that happen?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.2(2) &lt;SYSTEM&gt;&lt;/SYSTEM&gt;&lt;/P&gt;&lt;P&gt;hostname firewall001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; description Uplink to WAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.14&lt;/P&gt;&lt;P&gt; description DMZ&lt;/P&gt;&lt;P&gt; vlan 14&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.104&lt;/P&gt;&lt;P&gt; description Outside-104&lt;/P&gt;&lt;P&gt; vlan 104&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.200&lt;/P&gt;&lt;P&gt; description Outside-200&lt;/P&gt;&lt;P&gt; vlan 200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; description Downlink to LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.23&lt;/P&gt;&lt;P&gt; description MGMT-23&lt;/P&gt;&lt;P&gt; vlan 23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.24&lt;/P&gt;&lt;P&gt; description&amp;nbsp; MGMT-24&lt;/P&gt;&lt;P&gt; vlan 24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.500&lt;/P&gt;&lt;P&gt; description Client1-Inside&lt;/P&gt;&lt;P&gt; vlan 500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface ASA-Failover Ethernet0/3&lt;/P&gt;&lt;P&gt;failover link ASA-Failover Ethernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip ASA-Failover 10.0.1.1 255.255.255.252 standby 10.0.1.2&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin-context MAIN&lt;/P&gt;&lt;P&gt;context MAIN&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/0.14 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/0.200 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/1.23-Ethernet0/1.24 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Management0/0 &lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url disk0:/MAIN.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context CLIENT1&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/0.104 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/1.500 &lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url disk0:/CLIENT1.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Nov 2011 21:55:01 GMT</pubDate>
    <dc:creator>aimarchitect</dc:creator>
    <dc:date>2011-11-22T21:55:01Z</dc:date>
    <item>
      <title>How to trigger failover in a multi context ASA firewall environment?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878397#M492629</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the most common way to configure failover triggers on two ASA running in multiple context mode?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that there is any easy approach in which the standby takes over only if it loses connection with the primary on the configured "failover lan interface".&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What kind of other options are there?&amp;nbsp; What about configuring failover if either the trunking uplink (to WAN) or trunking downlink (to LAN) interfaces on the primary go down?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:54:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878397#M492629</guid>
      <dc:creator>aimarchitect</dc:creator>
      <dc:date>2019-03-11T21:54:09Z</dc:date>
    </item>
    <item>
      <title>How to trigger failover in a multi context ASA firewall environm</title>
      <link>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878398#M492632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The various failover triggers are listed here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Active/Standby:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_active_standby.html#wp1079547"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_active_standby.html#wp1079547&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Active/Active:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_active_active.html#wp1080167"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_active_active.html#wp1080167&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2011 21:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878398#M492632</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-11-22T21:11:11Z</dc:date>
    </item>
    <item>
      <title>How to trigger failover in a multi context ASA firewall environm</title>
      <link>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878399#M492637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;Thanks for the info.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Say I want to configure the standby to take over if the either the e0/0 trunk uplink to the WAN or the e0/1 trunk downlink to the LAN get disconnected (accidentally unplugged) on the primary... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would confugrure that in the system context, right?&amp;nbsp; If so, what would I add to the current primary system configuration to make that happen?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.2(2) &lt;SYSTEM&gt;&lt;/SYSTEM&gt;&lt;/P&gt;&lt;P&gt;hostname firewall001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; description Uplink to WAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.14&lt;/P&gt;&lt;P&gt; description DMZ&lt;/P&gt;&lt;P&gt; vlan 14&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.104&lt;/P&gt;&lt;P&gt; description Outside-104&lt;/P&gt;&lt;P&gt; vlan 104&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.200&lt;/P&gt;&lt;P&gt; description Outside-200&lt;/P&gt;&lt;P&gt; vlan 200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; description Downlink to LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.23&lt;/P&gt;&lt;P&gt; description MGMT-23&lt;/P&gt;&lt;P&gt; vlan 23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.24&lt;/P&gt;&lt;P&gt; description&amp;nbsp; MGMT-24&lt;/P&gt;&lt;P&gt; vlan 24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.500&lt;/P&gt;&lt;P&gt; description Client1-Inside&lt;/P&gt;&lt;P&gt; vlan 500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface ASA-Failover Ethernet0/3&lt;/P&gt;&lt;P&gt;failover link ASA-Failover Ethernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip ASA-Failover 10.0.1.1 255.255.255.252 standby 10.0.1.2&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin-context MAIN&lt;/P&gt;&lt;P&gt;context MAIN&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/0.14 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/0.200 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/1.23-Ethernet0/1.24 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Management0/0 &lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url disk0:/MAIN.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context CLIENT1&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/0.104 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface Ethernet0/1.500 &lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url disk0:/CLIENT1.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2011 21:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878399#M492637</guid>
      <dc:creator>aimarchitect</dc:creator>
      <dc:date>2011-11-22T21:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to trigger failover in a multi context ASA firewall envi</title>
      <link>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878400#M492640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You just need to enable interface monitoring for your sub-interfaces in the context where they are allocated. The ASA will then failover if the e0/0 link goes down or if the devices can't send/receive interface monitoring packets on any of the enabled subinterfaces. For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;firewall001# changeto context MAIN&lt;/P&gt;&lt;P&gt;firewall001/MAIN# conf t&lt;/P&gt;&lt;P&gt;firewall001/MAIN(config)# monitor-interface inside&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/command/reference/m.html#wp2123112"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/command/reference/m.html#wp2123112&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 13:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878400#M492640</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-11-23T13:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to trigger failover in a multi context ASA firewall envi</title>
      <link>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878401#M492642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Mike,&lt;/P&gt;&lt;P&gt;I see now that monitoring is configured within the context.&amp;nbsp; Failover from primary to standby in one context doesn't affect another context, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 22:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878401#M492642</guid>
      <dc:creator>aimarchitect</dc:creator>
      <dc:date>2011-11-23T22:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to trigger failover in a multi context ASA firewall envi</title>
      <link>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878402#M492644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It depends if you are using Active/Standby failover or Active/Active failover. With Active/Standby, all contexts are Active on the same unit at the same time and a failover event affects the entire unit. With Active/Active, you can assign your contexts to failover groups and a failover event may only affect one group and not the other. With Active/Active, one group is Active on one unit and the other group is Active on the second unit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Nov 2011 12:58:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-trigger-failover-in-a-multi-context-asa-firewall/m-p/1878402#M492644</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-11-24T12:58:08Z</dc:date>
    </item>
  </channel>
</rss>

