<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Active/Active FO in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370907#M837522</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;Hi Karuppuchamy,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;I have to appreciate your involvement and sharing your ideas with me. Thanks &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;Your answer mentioning that Firewall will not loadbalance intelligently like GLBP is very convincing and reasurring my understanding on the logic behind Cisco Active/Active. FW A/A logic is similar to MHSRP (A set of devices will have Context A as Default Gateway &amp;amp; another a set of devices will have Context B as Default Gateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;So I assume that, Active/Active will not solve the Failover time (Minimum Hello 500ms and Holdtime ) so, 1.5 sec delay cannot be avoided even when the firewall is configured in Active/Active . Am i correct ??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;Hope you will clarify this also&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;sairam&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Dec 2009 09:09:57 GMT</pubDate>
    <dc:creator>snarayanaraju</dc:creator>
    <dc:date>2009-12-30T09:09:57Z</dc:date>
    <item>
      <title>ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370901#M837499</link>
      <description>&lt;DIV class="utdU2e"&gt; &lt;/DIV&gt;&lt;DIV class="QqXVeb"&gt; &lt;/DIV&gt;&lt;DIV class="ii gt" id=":s2"&gt;Hi Experts,&lt;P&gt;&lt;/P&gt;I am analysing ASA / FWSM active / active configuration. I understood that two context has to be created minimum to achieve this task. I also&lt;BR /&gt;understood that each context will be in different network.&lt;P&gt;&lt;/P&gt;If so and If I have only one network say VLAN 5 (&lt;A href="http://192.168.1.0/" target="_blank"&gt;192.168.1.0/&lt;/A&gt; 24), is it possible to achive Active/Active failover for&amp;nbsp; the users.?&lt;P&gt;&lt;/P&gt;Please help to clarify and thanks in advance&lt;P&gt;&lt;/P&gt;sairam&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370901#M837499</guid>
      <dc:creator>snarayanaraju</dc:creator>
      <dc:date>2019-03-11T16:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370902#M837503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can configure PIX/ASA/FWSM in the following scenarios.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.atleast we have to configure 2 contexts and we have to allocate these context into failover groups&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.If you are running the firewall in routing mode then atleast you should have minimum 2 networks i.e) one inside interface and other one is outside interface per context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.If you want to configure in FWSM same condition needs to be apply as i said in point number 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For further more information, please have a look in this file from cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml&lt;/A&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;&lt;EM&gt;Karuppuchamy, CCIE&lt;/EM&gt;(R&amp;amp;S)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Dec 2009 09:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370902#M837503</guid>
      <dc:creator>KARUPPUCHAMY MALAIYANDI</dc:creator>
      <dc:date>2009-12-29T09:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370903#M837505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;Hi &lt;/SPAN&gt;&lt;SPAN style="color: #000000; "&gt;Karuppuchamy,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; "&gt;Thanks for your prompt response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; "&gt;Your quoted point are acceptable and I am aggreeing cent percent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; "&gt;But my questio is very specific. Let me repeat it again for your best understanding..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;"If I have only one VLAN (network), whether it is possobile to have Active/Active FO, so that traffic from these network will pass through both the Firewalls&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; "&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; "&gt;sairam&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Dec 2009 10:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370903#M837505</guid>
      <dc:creator>snarayanaraju</dc:creator>
      <dc:date>2009-12-29T10:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370904#M837509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sairam,&lt;/P&gt;&lt;P&gt;If you have only one vlan what is the need for a firewall? To firewall this one vlan's traffic from going where? Is this an internet facing firewall? Why do you want this traffic to traverse both context? Is there assymetry involved? One reason to go active active is to allow assymeterical traffic but, now with the latest code we have tcp state-bypass to accomplish that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Active active is configured so we can load balance and use both the firewalls by, making some contexts active on one firewall while having the other contexts active on the other firewall so, the expensive piece of hardware is not sitting dormant waiting to function only when there is a problem with one firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Dec 2009 12:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370904#M837509</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-29T12:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370905#M837515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sankar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes I have one VLANs say VLAN 1 as INSIDE users. This Firewall is internet facing and have 2 Zones INSIDE &amp;amp; OUTSIDE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My understanding is CONTEXT A in Firewall 1 is ACTIVE &amp;amp; CONTEXT B in Firewall 2 is active. Whether both CONTEXTs can be in same network as VLAN 1 network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I understand that VLAN 1 users have default gateway as Either as CONTEXT A or CONTEXT B. If Both these Contexts should be in different network, how will be the default gateway of the INSIDE users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG style="color: #ff0000; "&gt;Firewall is not intelligently load balance the traffic as GLBP do. I think Firewall Active / Active is just work like MHSRP. Is it so??&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whether My understanding is correct.? Expecting your valuable comments please&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sairam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Dec 2009 06:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370905#M837515</guid>
      <dc:creator>snarayanaraju</dc:creator>
      <dc:date>2009-12-30T06:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370906#M837521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;Weather both context can be in the same network&lt;/STRONG&gt;&lt;/SPAN&gt; --- yes, it can be,because it's routing table and cfg files all together different.so we can use the same network for different context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when we are using the same network segement that is vlan 1 in both context,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if the we are using different ip's for both context, then the user has to change his gateway.If the user want to send the traffic via context A then he has to change his gateway IP as context A vlan1 ip address and vice-versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we are using the same ip address for both context A and context B then it may lead into ARP entry problem.becuase you have to connect the firewall into L2 switch,where all the users are connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;Firewall is not intelligently load balance the traffic&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp; --- Yes.It will not to load balance intellegently.Active-Active fsailover in the sense, we can the user firewall hardware efficiently.nothing more.rest-all it is just like active-standby.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Active-Standby failover, one firewall will always sit idle...there is no use of that firewall.If Primary fails,then only it wil be useful.To avoid these issues,&lt;/P&gt;&lt;P&gt;we can configure active-active failover.We can use the hardware efficiently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this will help u.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&lt;STRONG&gt;Karuppuchamy CCIE(R&amp;amp;S),CCSP&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-GB" style="font-size: 9pt; font-family: Arial;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id="_x0000_t75"  coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe"  filled="f" stroked="f"&gt; &lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt; &lt;v:formulas&gt; &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt; &lt;/v:formulas&gt; &lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt; &lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt; &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style='width:77.25pt;  height:49.5pt' o:ole=""&gt; &lt;v:imagedata src="file:///C:\DOCUME~1\KARUPP~1.MAL\LOCALS~1\Temp\msohtml1\01\clip_image001.emz"   o:title=""&gt;&lt;/v:imagedata&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;IMG height="66" src="https://community.cisco.com/" width="103" /&gt;&lt;!--[endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:OLEObject Type="Embed" ProgID="Package" ShapeID="_x0000_i1025"   DrawAspect="Icon" ObjectID="_1323689373"&gt; &lt;/o:OLEObject&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-GB" style="font-size: 9pt; font-family: Arial;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id="_x0000_t75"  coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe"  filled="f" stroked="f"&gt; &lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt; &lt;v:formulas&gt; &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt; &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt; &lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt; &lt;/v:formulas&gt; &lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt; &lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt; &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style='width:77.25pt;  height:49.5pt' o:ole=""&gt; &lt;v:imagedata src="file:///C:\DOCUME~1\KARUPP~1.MAL\LOCALS~1\Temp\msohtml1\01\clip_image001.emz"   o:title=""&gt;&lt;/v:imagedata&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;IMG height="66" src="https://community.cisco.com/" width="103" /&gt;&lt;!--[endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:OLEObject Type="Embed" ProgID="Package" ShapeID="_x0000_i1025"   DrawAspect="Icon" ObjectID="_1323689369"&gt; &lt;/o:OLEObject&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Dec 2009 06:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370906#M837521</guid>
      <dc:creator>KARUPPUCHAMY MALAIYANDI</dc:creator>
      <dc:date>2009-12-30T06:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370907#M837522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;Hi Karuppuchamy,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;I have to appreciate your involvement and sharing your ideas with me. Thanks &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;Your answer mentioning that Firewall will not loadbalance intelligently like GLBP is very convincing and reasurring my understanding on the logic behind Cisco Active/Active. FW A/A logic is similar to MHSRP (A set of devices will have Context A as Default Gateway &amp;amp; another a set of devices will have Context B as Default Gateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;So I assume that, Active/Active will not solve the Failover time (Minimum Hello 500ms and Holdtime ) so, 1.5 sec delay cannot be avoided even when the firewall is configured in Active/Active . Am i correct ??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;Hope you will clarify this also&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;sairam&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Dec 2009 09:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370907#M837522</guid>
      <dc:creator>snarayanaraju</dc:creator>
      <dc:date>2009-12-30T09:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370908#M837525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG style="color: #0000ff; "&gt;&lt;SPAN style="color: #ff00ff;"&gt;so, 1.5 sec delay cannot be avoided even when the firewall is configured in Active/Active . Am i correct ??&lt;/SPAN&gt;&amp;nbsp; --- &lt;SPAN style="color: #000000;"&gt;Yes..&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In both the failover scenarios (active-active and active - standby) we cannot avoid this situation.When we are doing faiolver in live network,For data traffic there will no impact&amp;nbsp; but voice traffic will get impact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this will helps you to understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&lt;STRONG&gt;Karuppuchamy CCIE(R&amp;amp;S),CCSP&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Dec 2009 09:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370908#M837525</guid>
      <dc:creator>KARUPPUCHAMY MALAIYANDI</dc:creator>
      <dc:date>2009-12-30T09:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370909#M837529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Karuppachmi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will rate this as extremly helpful and answer. Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sairam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Dec 2009 11:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370909#M837529</guid>
      <dc:creator>snarayanaraju</dc:creator>
      <dc:date>2009-12-30T11:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Active FO</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370910#M837535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also achieve load balancing without splitting the devices into different sets and setting them different Default GWs. If you have routers in front of and behind the firewalls (contexts), that are capable of doing equal path load balancing (IOS routers and L3 switches do), you can let the router to manage the load balancing, either per-flow or even per-packet. The 'per-flow' method is the default and recommended, especialy if there are firewalls in the mid-path. In the IOS case the load balancing is supported with both static and dynamic routing. Having CEF enabled on the routers and having equal routing path costs all the way router-to-router for each L3 path are critical to get things realy work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vasil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jan 2010 18:03:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-fo/m-p/1370910#M837535</guid>
      <dc:creator>vmilanov</dc:creator>
      <dc:date>2010-01-04T18:03:35Z</dc:date>
    </item>
  </channel>
</rss>

