<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Active/Active vs Active/Standby in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453810#M534532</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I thought in active active traffic flows through both firewalls only if you have 2 different context groups with a different context on each firewall active at the same time.  I.E. customer A context active on Primary and customer B context active on Secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewall only needs one customer configuration then is there any point using active active?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Aug 2005 09:11:16 GMT</pubDate>
    <dc:creator>firestartest</dc:creator>
    <dc:date>2005-08-08T09:11:16Z</dc:date>
    <item>
      <title>PIX Active/Active vs Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453808#M534530</link>
      <description>&lt;P&gt;Can anyone tell me what the main advantage of A/A is compared to A/S.  For single firewall mode the failover occurs the same speed and stateful connections are passed to the standby unit.  For A/A you need multiple context mode which means you cant use VPN, Dynmic Routing.  I have configured both methods and testing FTP downloads when a failover occurs.  I cannot see what the advantage of A/A is compared to A/S.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453808#M534530</guid>
      <dc:creator>firestartest</dc:creator>
      <dc:date>2020-02-21T08:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Active/Active vs Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453809#M534531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in active active failover you are utilizing both of your firewalls. traffic is flowing through both the firewall's active contexts. where as in active/standby one firewall is just sitting idle to take over once failure happens on primary&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2005 16:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453809#M534531</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-08-05T16:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Active/Active vs Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453810#M534532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I thought in active active traffic flows through both firewalls only if you have 2 different context groups with a different context on each firewall active at the same time.  I.E. customer A context active on Primary and customer B context active on Secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewall only needs one customer configuration then is there any point using active active?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2005 09:11:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453810#M534532</guid>
      <dc:creator>firestartest</dc:creator>
      <dc:date>2005-08-08T09:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Active/Active vs Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453811#M534533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;if I have understood correctly the active/active mechanism, you can configure two different context groups defining, somehow, two different types of traffic flows f.i., if you can.&lt;/P&gt;&lt;P&gt;Anyway I understood also that the only result you obtain is a static load sharing, not load balancing, and failover.&lt;/P&gt;&lt;P&gt;It is pretty much like having two HSRP groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know if anyone else agree or can explain me how it really works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2005 12:15:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453811#M534533</guid>
      <dc:creator>bangelucci</dc:creator>
      <dc:date>2005-08-10T12:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Active/Active vs Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453812#M534534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what I have read the active active mechanism basically means you have 2 groups.  1 active on Primary and 1 active on Secondary.  So if you have 4 contexts (engineering, sales, support, marketing)  2 of thses (engineering, sales) could be active on group 1 which is Primary.  The other 2 (support, marketing) wouold be active on group 2 which would be the secondary firewall.  This means thet group 1 is in standby state on secondary and group 2 is on standby state on primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is how I understand it.  Someone correct me if i'm wrong.  I just cannot understand what the advantage is going to active/active mode for a single installation i.e. only one firewall context needed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2005 14:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453812#M534534</guid>
      <dc:creator>firestartest</dc:creator>
      <dc:date>2005-08-10T14:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Active/Active vs Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453813#M534536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are right.&lt;/P&gt;&lt;P&gt;unless you have two contexts, you will not be utilizing the active/active feature. so there doesn't seem to be any advantage there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2005 16:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453813#M534536</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-08-10T16:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Active/Active vs Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453814#M534538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone deploy Active/Active configuration ?&lt;/P&gt;&lt;P&gt;According to description of Version 7.x, we have to buy &lt;/P&gt;&lt;P&gt;4 units to do A/A topo ? A/A included pair of A/S ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgds&lt;/P&gt;&lt;P&gt;Khanh    &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2005 02:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-active-active-vs-active-standby/m-p/453814#M534538</guid>
      <dc:creator>khanhlq</dc:creator>
      <dc:date>2005-09-08T02:31:40Z</dc:date>
    </item>
  </channel>
</rss>

