<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Single IP Failover Pair in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375666#M760097</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok.. What I understand is I can make a failover pair with single ip, but for cannot monitor, login to standby asa thru outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you send the configurarion (link) for the same.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Feb 2010 05:29:48 GMT</pubDate>
    <dc:creator>manuadoor</dc:creator>
    <dc:date>2010-02-26T05:29:48Z</dc:date>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375663#M760079</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My internet leased line will be terminated on an ASA 5510 which is in Active/Passive Failover. My problem is I have got a /30 address range from ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total 2 IPs, one IP will be in ISP router.. and only 1 left for me.. I cannot use any extra device between ASA and ISP router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manu B.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375663#M760079</guid>
      <dc:creator>manuadoor</dc:creator>
      <dc:date>2019-03-11T17:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375664#M760085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately not much to do here....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need at least a /29 mask to allow an IP to both ASA's outside interfaces besides the default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can ask your ISP for a /29 range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Feb 2010 15:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375664#M760085</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-02-25T15:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375665#M760089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Failover will work just fine, the only problem would be for monitoring the interfaces and if you would like to log in to the standby from the outside you would have no ip available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many people run failover with no standby ip addresses. Not the ideal solution but failover will still work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Feb 2010 22:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375665#M760089</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-02-25T22:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375666#M760097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok.. What I understand is I can make a failover pair with single ip, but for cannot monitor, login to standby asa thru outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you send the configurarion (link) for the same.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 05:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375666#M760097</guid>
      <dc:creator>manuadoor</dc:creator>
      <dc:date>2010-02-26T05:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375667#M760102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Here is the link that has it &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1058096"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1058096&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 14:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375667#M760102</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-02-26T14:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375668#M760106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mandor,&lt;/P&gt;&lt;P&gt;No standby IP on the outside interface is very common. A lot of people are in the same situation as you.&amp;nbsp; It may be simply incomplete configuration according to Cisco but, it certainly does not affect failover from working.&amp;nbsp; If the primary/active unit were to fail due to some hardware failure certainly the secondary/standby unit will take over and become the active unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution to this problem is to use private IP between the firewall and the router and then use the /30 address space on&amp;nbsp; the router facing the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside network----(IN)ASA(OUT)----Private_IP---Router---Public /30 IP---Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 14:23:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375668#M760106</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-02-26T14:23:07Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375669#M760110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a valid cisco supported configuration - If i use this method (/30 on outside) on my pair of ASAs and have an issue that I need to contact the tac about, will they support me with this configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DGW&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Aug 2012 22:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375669#M760110</guid>
      <dc:creator>dylan.webb</dc:creator>
      <dc:date>2012-08-13T22:02:35Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375670#M760115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using dynamic routing on the ASA, then not having a standby IP address will be a problem because in case of a failover, the ASA will not clear its routing table and reset the process. It needs an IP address on the interface to clear that. &lt;/P&gt;&lt;P&gt;Without a standby IP address, the ASA will leave the duplicate routes in place when the unit becomes active until they are cleared manually. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 01:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375670#M760115</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2012-08-14T01:17:37Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375671#M760116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Is this a valid cisco supported configuration and will the Cisco TAC support this configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DGW&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 01:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375671#M760116</guid>
      <dc:creator>dylan.webb</dc:creator>
      <dc:date>2012-08-14T01:24:26Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375672#M760117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont see a reason why they wont support it. ASA provides the flexibility of using a single IP address for failover to work. If they didnt support it, i am sure the feature would not be there &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, if you face an issue with failover, the first thing that they will tell you is to use a standby IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 01:28:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375672#M760117</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2012-08-14T01:28:45Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375673#M760118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zujalal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't understand why is going to be a problew if you are using dynamyc routing and you don't have stand by ip configurated. Why is going to be duplicated routes? Would you be more especific?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 11:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375673#M760118</guid>
      <dc:creator>javi_cesp</dc:creator>
      <dc:date>2013-01-17T11:13:53Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375674#M760119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have to use the ISP router, can you connect the cable directly to the ASA?&amp;nbsp; Also can't you get more IP's from your ISP like a /29&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 17:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375674#M760119</guid>
      <dc:creator>ALIAOF_</dc:creator>
      <dc:date>2013-01-17T17:41:26Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375675#M760120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;since we have same ip configured "No standby ip " on outside interface of both ASA , when there is a failover , there will be a&amp;nbsp; change in the MAC addreess associated with the outside ip address right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the isp will see a different mac each time during a failover from asa 1 to 2 or 2 to 1 .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 08:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375675#M760120</guid>
      <dc:creator>cisconell</dc:creator>
      <dc:date>2013-03-19T08:04:01Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375676#M760122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The MAC address should be unchanged when a failover occurs. The Standby ASA inherits both the IP address and the same MAC address the previous Active unit was using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise normally you would probably have downtime in the network connections if the ARP on the upstream router hasnt been updated to the new MAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 08:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375676#M760122</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-03-19T08:53:29Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375677#M760123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you mean even though we dont configure standby ip on the outside interface ...instead we have same ip address on both asa on outside interface there will not be any change in MAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what make different in failover when we have ASA with standby ip configured on outside interface and with out standbyip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My&amp;nbsp; Understanding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.In both case failover happen successfully&lt;/P&gt;&lt;P&gt;2.No change in mac &lt;/P&gt;&lt;P&gt;3.monitor interface can be enabled on outside interface in both case .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 16:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375677#M760123</guid>
      <dc:creator>cisconell</dc:creator>
      <dc:date>2013-03-19T16:06:16Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375678#M760124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;cisconell,&lt;/P&gt;&lt;P&gt;That is correct. There is only one active IP and standby IP. In your case the standby IP is 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only problem with that is you cannot monitor the interface. &lt;/P&gt;&lt;P&gt;Failover will work perfectly fine but, Cisco recommends that you have an IP address configured as standby IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 16:10:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375678#M760124</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2013-03-19T16:10:05Z</dc:date>
    </item>
    <item>
      <title>Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375679#M760125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Kureli,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only problem with that is you cannot monitor the interface. -------which mean when the outiside interface of ASA 1 goes down it will not failover to ASA 2 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or it even dont accept to apply the config monitor interface outside ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 09:39:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/1375679#M760125</guid>
      <dc:creator>cisconell</dc:creator>
      <dc:date>2013-03-20T09:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Single IP Failover Pair</title>
      <link>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/3195864#M760126</link>
      <description>&lt;P&gt;Dear Kureli,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have the same issues from my ISP i&amp;nbsp; have only one IP, so the failover will work fine right ?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 10:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/single-ip-failover-pair/m-p/3195864#M760126</guid>
      <dc:creator>geo</dc:creator>
      <dc:date>2017-10-09T10:14:53Z</dc:date>
    </item>
  </channel>
</rss>

