<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5520: Configuring Active/Standby High Availability in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792558#M494217</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To clear the configuration for failover you can use this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear configure failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this shoudl work for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Nov 2011 17:08:56 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2011-11-03T17:08:56Z</dc:date>
    <item>
      <title>ASA 5520: Configuring Active/Standby High Availability</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792555#M494199</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to Cisco firewalls. We are moving from a different vendor to Cisco ASA 5520s. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two ASA 5520s running ASA 8.2(5). I am managing them with ASDM 6.4(5). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to setup Active/Standby using the High Availability Wizard. I have interfaces on each device setup with just an IP address and subnet mask. Primary is 10.1.70.1/24 and secondary is 10.1.70.2/24. The interfaces are connected to a switch and these interfaces are the only nodes on this switch. When I run the Wizard on the primary, configure for Active/Standby, enter the peer IP of 10.1.70.2 and I get an error message saying that the peer test failed, followed by an error saying ASDM is temporarily unable to connect to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried this using a crossover cable to connect the interfaces directly with the same result. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792555#M494199</guid>
      <dc:creator>dan</dc:creator>
      <dc:date>2019-03-11T21:45:34Z</dc:date>
    </item>
    <item>
      <title>ASA 5520: Configuring Active/Standby High Availability</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792556#M494203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We may need to use some CLI here. When you put the IP addresses on the devices, are they reachable towards each other? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is weird that it dies right after the ASA does the ping test. It would be better if you run this configuration via command line thou, it will give you more mechanisms in order to see what is happening. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Nov 2011 22:28:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792556#M494203</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-02T22:28:58Z</dc:date>
    </item>
    <item>
      <title>ASA 5520: Configuring Active/Standby High Availability</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792557#M494210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I am working on setting up failover using CLI. I've entered the config on the primary and that seemed successful. Before I move on to the secondary I'd like to start over with the failover config on the primary. I'm just learning this stuff and want to go over it a few times to really understand what I'm doing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to I completely clear the failover configuration on the primary?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Nov 2011 16:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792557#M494210</guid>
      <dc:creator>dan</dc:creator>
      <dc:date>2011-11-03T16:57:48Z</dc:date>
    </item>
    <item>
      <title>ASA 5520: Configuring Active/Standby High Availability</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792558#M494217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To clear the configuration for failover you can use this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear configure failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this shoudl work for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Nov 2011 17:08:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792558#M494217</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-11-03T17:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520: Configuring Active/Standby High Availability</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792559#M494221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The command Varun is right. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you want to know a little bit more about this stuff, here goes a bit. Every interface will have a secondary IP and a Primary IP where the Active/Standby pair will exchange hello packes. If the hellos are not heard from mate, the the unit is delcare failed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case the primary is the one that gets an interface down, it will failover to the other unit, if it is the standby that has the problem, the active unit will declare the other Unit "standby failed). You will know that everything is alright when you do a show failover and the standby pair shows "Standby Ready". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For configuring it, just put a secondary IP on every interface to be monitored (If by any chance you dont have an available secondary IP for one of the interfaces you can avoid monitoring the given interface using the command no "monitor-interface &lt;EM&gt;nameif"&lt;/EM&gt; where the nameif is the name of the interface without the secondary IP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then put the commands for failover and stateful link, the stateful link will copy the connections table (among other things) to avoid downtime while passing from One unit to another, This link should have at least the same speed as the regular data interfaces. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure the failover link and the stateful link in just one interface, by just using the same name for the link, remember that this link will have a totally sepparate subnet from the ones already used in firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the configuration &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover gig0/3&lt;/P&gt;&lt;P&gt;failover link failover gig0/3 &lt;/P&gt;&lt;P&gt;failover interface ip failover 10.1.0.1 255.255.255.0 standby 10.1.0.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover lan unit secondary&lt;/P&gt;&lt;P&gt;failover lan interface failover gig0/3&lt;/P&gt;&lt;P&gt;failover link failover gig0/3 &lt;/P&gt;&lt;P&gt;failover interface ip failover 10.1.0.1 255.255.255.0 standby 10.1.0.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that you can ping each other secondary/primary IP and then put the command&lt;/P&gt;&lt;P&gt;failover first on the primary and then on the secondary. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have further doubts. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Link for reference&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008080dfa7.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008080dfa7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Nov 2011 18:00:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792559#M494221</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-03T18:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520: Configuring Active/Standby High Availability</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792560#M494226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you both for your quick and accurate replies! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able clear the previous failover config and re-config using Mike's outline. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate your help. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Nov 2011 19:16:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/1792560#M494226</guid>
      <dc:creator>dan</dc:creator>
      <dc:date>2011-11-03T19:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520: Configuring Active/Standby High Availability</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/4003792#M494230</link>
      <description>&lt;P&gt;So, If I want to do Active/Active with Wizard, what IP do I use? I have two 5520's in Active/Standby. I connect to console of each and only 1 thing is different (see below) How do I give a different IP for the wizard? Do I remove failover?&lt;BR /&gt;&lt;BR /&gt;Primary&lt;BR /&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;Secondary&lt;/P&gt;&lt;P&gt;failover lan unit secondary&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2019 21:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/4003792#M494230</guid>
      <dc:creator>jroy777</dc:creator>
      <dc:date>2019-12-26T21:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520: Configuring Active/Standby High Availability</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/4003829#M494234</link>
      <description>&lt;P&gt;Active-active only applies to multi-context configurations with ASAs. The wizard only accommodates the basic single context Active-Standby setup.&lt;/P&gt;
&lt;P&gt;There are several examples online that go into detail on how to setup active-active. Here's a very good one:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0001114" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0001114&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;..and the official Cisco configuration guide section:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ha_active_active.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ha_active_active.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 01:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuring-active-standby-high-availability/m-p/4003829#M494234</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-12-27T01:52:48Z</dc:date>
    </item>
  </channel>
</rss>

