<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IOS CBFW firewall HA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752523#M496196</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have anyone deploy HA on IOS firewall with Fastethernet interface configured into multiple sub-interfaces and tag with different vlan-Id and is assign as inside interfaces. Serial interface is outside interface. Would like to know whether HA can be apply in such design and whether it works ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:35:37 GMT</pubDate>
    <dc:creator>jason.kwang</dc:creator>
    <dc:date>2019-03-11T21:35:37Z</dc:date>
    <item>
      <title>IOS CBFW firewall HA</title>
      <link>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752523#M496196</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have anyone deploy HA on IOS firewall with Fastethernet interface configured into multiple sub-interfaces and tag with different vlan-Id and is assign as inside interfaces. Serial interface is outside interface. Would like to know whether HA can be apply in such design and whether it works ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:35:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752523#M496196</guid>
      <dc:creator>jason.kwang</dc:creator>
      <dc:date>2019-03-11T21:35:37Z</dc:date>
    </item>
    <item>
      <title>IOS CBFW firewall HA</title>
      <link>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752524#M496197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you mean by HA? afaik HA is done through FHRPs like HSRP,VRRP or GLBP and they all demand at least 2 routers.I think it should work as long as active/standy can communicate they state which they will as by default traffic from/to self is permitted.&lt;/P&gt;&lt;P&gt;Can you tell if this is what you want to do ? if so I'll lab it up quickly and confirm or not what I said above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 08:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752524#M496197</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-10-10T08:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: IOS CBFW firewall HA</title>
      <link>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752525#M496198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, you are partlly right abt my question. Yes I mean 2 routers running hsrp. But also following command on the 2 router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Redundancy inter-device&lt;/P&gt;&lt;P&gt; Scheme standby &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is relatively new commands. I have no routers to test out !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    &lt;/P&gt;&lt;P&gt;     &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 09:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752525#M496198</guid>
      <dc:creator>jason.kwang</dc:creator>
      <dc:date>2011-10-10T09:33:10Z</dc:date>
    </item>
    <item>
      <title>IOS CBFW firewall HA</title>
      <link>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752526#M496199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok gonna lab it up and tell you what.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 09:44:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752526#M496199</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-10-10T09:44:36Z</dc:date>
    </item>
    <item>
      <title>IOS CBFW firewall HA</title>
      <link>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752527#M496200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Did you manage to lab the router as firewalls in HA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm just about to purchase 2x 2901 to run as firewalls to protect my network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But would like to configure them in active/stanby?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 11:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752527#M496200</guid>
      <dc:creator>martinbuffleo</dc:creator>
      <dc:date>2011-11-23T11:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: IOS CBFW firewall HA</title>
      <link>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752528#M496201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Sorry but I couldn't test because I didn't know about these 2 commands:&lt;/P&gt;&lt;P&gt;Redundancy inter-device&lt;/P&gt;&lt;P&gt; Scheme standby &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I must admit as there was no new post from you it gout out of my head.&lt;/P&gt;&lt;P&gt;Do you really need these 2 commands? otherwise post your topology and requirements and i'll do it tomorrow or on friday.&lt;/P&gt;&lt;P&gt;I don't have any 2901 or ISR G2 to test but only GNS3 and I'll have to use the SNAT feature which may be unavailable on the newer platforms as it is phased out by Cisco and they recommend using active/standby or active/active ASA pair for replacement of this technology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 12:58:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752528#M496201</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-11-23T12:58:22Z</dc:date>
    </item>
    <item>
      <title>IOS CBFW firewall HA</title>
      <link>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752529#M496202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It wasn't my thread I'm just jumping on the back of it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 13:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-cbfw-firewall-ha/m-p/1752529#M496202</guid>
      <dc:creator>martinbuffleo</dc:creator>
      <dc:date>2011-11-23T13:04:24Z</dc:date>
    </item>
  </channel>
</rss>

