<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA Heartbeart Failover (Direct Connection) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-heartbeart-failover-direct-connection/m-p/1653724#M558634</link>
    <description>&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;Hi There&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;I need some advice please. Currently, my customer has 2 units of Cisco PIX 515E running on Active/Standby mode. As for the heartbeat link, there are 2 dedicated switches placed in between both the Cisco PIX 515E i.e. FW1 --&amp;gt; SW1 --&amp;gt; SW2 --&amp;gt; FW2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;My customer will be changing both the Cisco PIX 515E to Cisco ASA 5510. Now, they are asking me, since they will be using Cisco ASA 5510 eventually, can the heartbeat link be a direct UTP cross cable or must the 2 switches in between still exist?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;I remember I have tested this before, few years back, in the event I were to pull out the UTP cross cable that's connecting both the Cisco ASA 5510 Firewalls directly (without any switches in between), the Active/Standby mode still works fine. It doesn't go bad whereby both the Cisco ASA 5510 suddenly becomes Active/Active, and causes network issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;Can someone confirm this please? Are switches required for the heartbeat link in a Cisco ASA environment or can a direct UTP cross cable connection be adequate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;Ram&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:16:15 GMT</pubDate>
    <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
    <dc:date>2019-03-11T20:16:15Z</dc:date>
    <item>
      <title>Cisco ASA Heartbeart Failover (Direct Connection)</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-heartbeart-failover-direct-connection/m-p/1653724#M558634</link>
      <description>&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;Hi There&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;I need some advice please. Currently, my customer has 2 units of Cisco PIX 515E running on Active/Standby mode. As for the heartbeat link, there are 2 dedicated switches placed in between both the Cisco PIX 515E i.e. FW1 --&amp;gt; SW1 --&amp;gt; SW2 --&amp;gt; FW2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;My customer will be changing both the Cisco PIX 515E to Cisco ASA 5510. Now, they are asking me, since they will be using Cisco ASA 5510 eventually, can the heartbeat link be a direct UTP cross cable or must the 2 switches in between still exist?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;I remember I have tested this before, few years back, in the event I were to pull out the UTP cross cable that's connecting both the Cisco ASA 5510 Firewalls directly (without any switches in between), the Active/Standby mode still works fine. It doesn't go bad whereby both the Cisco ASA 5510 suddenly becomes Active/Active, and causes network issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;Can someone confirm this please? Are switches required for the heartbeat link in a Cisco ASA environment or can a direct UTP cross cable connection be adequate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; Tahoma&amp;amp;quot: ; sans-serif&amp;amp;quot: ; font-family: courier new,courier; ,&amp;amp;quot: ; "&gt;Ram&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-heartbeart-failover-direct-connection/m-p/1653724#M558634</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2019-03-11T20:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Heartbeart Failover (Direct Connection)</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-heartbeart-failover-direct-connection/m-p/1653725#M558642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use any of the 2 methods, as there is no issue with any of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the URL for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_overview.html#wp1077551"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_overview.html#wp1077551&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please also note:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="1" /&gt;The&amp;nbsp; adaptive security appliance supports Auto-MDI/MDIX on its copper&amp;nbsp; Ethernet ports, so you can either use a crossover cable or a&amp;nbsp; straight-through cable. If you use a straight-through cable, the&amp;nbsp; interface automatically detects the cable and swaps one of the&amp;nbsp; transmit/receive pairs to MDIX. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Apr 2011 05:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-heartbeart-failover-direct-connection/m-p/1653725#M558642</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-04-04T05:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Heartbeart Failover (Direct Connection)</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-heartbeart-failover-direct-connection/m-p/1653726#M558649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer&lt;/P&gt;&lt;P&gt;Thank you so much for your kind feedback, as always. I understand that both method works. In fact, I just saw this statement in this URL as well &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/failover.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/failover.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, which one of these method is classified as Cisco's best practise? both methods are Cisco's best practise or the method with the switch in between both the Firewall's heartbeat link?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Apr 2011 05:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-heartbeart-failover-direct-connection/m-p/1653726#M558649</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2011-04-04T05:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Heartbeart Failover (Direct Connection)</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-heartbeart-failover-direct-connection/m-p/1653727#M558652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Best practise would be to use a switch because it would be easier for troubleshooting purposes when you investigate failure, as the switch port will tell you that there is an interface failure.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Apr 2011 05:12:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-heartbeart-failover-direct-connection/m-p/1653727#M558652</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-04-04T05:12:09Z</dc:date>
    </item>
  </channel>
</rss>

