<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Active/Standby in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339272#M858661</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to dedicate an interface on each ASA for failover.  These interfaces can either connect back to your core switches on an isolated VLAN or can be connected directly with a crossover cable.  Please refer to the following doc for failover requirements and configuration on the ASA platform.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Jul 2009 17:41:24 GMT</pubDate>
    <dc:creator>Todd Pula</dc:creator>
    <dc:date>2009-07-14T17:41:24Z</dc:date>
    <item>
      <title>ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339271#M858660</link>
      <description>&lt;P&gt;Couple questions. About to implement this scenario with two ASA5520s. I plan to have these two connected to two 4506s running as core switches. My question is do the ASAs need a dedicated link to each other for their communication or can they communicate active/standby info with each other through their links to the dual 4506s? The 4506s will be running EIGRP with default routes to the ASAs.  The 4 devices will be connected with a /29 subnet. Please see the attachment. The ASAs do not have sub interfaces. They are connected to the 4506s on the same vlan, vlan 2. Will i need a direct link between the two ASAs? Thanks. I just want to make sure i understand this right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339271#M858660</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2019-03-11T15:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339272#M858661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to dedicate an interface on each ASA for failover.  These interfaces can either connect back to your core switches on an isolated VLAN or can be connected directly with a crossover cable.  Please refer to the following doc for failover requirements and configuration on the ASA platform.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2009 17:41:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339272#M858661</guid>
      <dc:creator>Todd Pula</dc:creator>
      <dc:date>2009-07-14T17:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339273#M858662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1058096" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1058096&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2009 17:42:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339273#M858662</guid>
      <dc:creator>Todd Pula</dc:creator>
      <dc:date>2009-07-14T17:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339274#M858663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so i would keep my current IP config but add 1 more interface per ASA and connect them to a layer 2 vlan on the dual cores? Also i have a question about my default routes on the dual 4506s. As i mentioned i'm running EIGRP on the 4506s. Since i'll have two 4506s and 2 ASAs what will my default route point to?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2009 17:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339274#M858663</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2009-07-14T17:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339275#M858664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your existing IP config will need to be updated to include standby IP addresses for the pair.  In an active/standby scenario, the active ASA will manage the primary interface IPs and will use the failover link for replication and keepalives.  In a failure scenario, the secondary ASA will take over control of the primary interface IPs.  This will allow you to point your default route to the same IP irrespective of what ASA is active at that time.  Below is a sample failover config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 11.11.11.11 255.255.255.0 standby 11.11.11.12 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.10.11 255.255.255.0 standby 10.10.10.12 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface Failover GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;failover key *****&lt;/P&gt;&lt;P&gt;failover link Failover GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;failover interface ip Failover 10.1.1.1 255.255.255.252 standby 10.1.1.2   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2009 19:03:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339275#M858664</guid>
      <dc:creator>Todd Pula</dc:creator>
      <dc:date>2009-07-14T19:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339276#M858665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice, you answered my question.                Any issues running this on a production ASA or should i wait until a maintenance window?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2009 19:08:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339276#M858665</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2009-07-14T19:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339277#M858667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One last question....I see you have a Standby IP on the OUTSIDE interface...is this needed? I have a public IP on my ASAs OUTSIDE interface, would i need a second public IP for the second ASA OUTSIDE int?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2009 19:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339277#M858667</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2009-07-14T19:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339278#M858669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will want both the inside and outside interfaces configured with a secondary address.  This address must be from the same subnet as the active IP address.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2009 20:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339278#M858669</guid>
      <dc:creator>Todd Pula</dc:creator>
      <dc:date>2009-07-14T20:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339279#M858670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've read through some documentation and see where Cisco recommends adding the secondary IP address for all data interfaces. I am trying to understand how certain things like S2S and remote access  VPNs will work now. We have several remote ASAs that use the primary public IP for S2S and clients that are configured to use the primary public IP. Could you explain this a little more? Thank you so much for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2009 22:47:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339279#M858670</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2009-07-14T22:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339280#M858671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This not secondary address but, standby address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rolls are primary and secondary but the states are active and standby.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which ever unit is active it will assume the active mac in layer 2 and the active IP for layer 3. This active mac and active IP is always the primary unit's except the failover interface.  These will continue to use their own IP and mac.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we failover we always send gratuitous arp so, the adjacent devices can update the arp and mac-address table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, even for the outside interface you should have a standby IP otherwise monitoring interfaces will not be possible.  Failover will still work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2009 23:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339280#M858671</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-07-14T23:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339281#M858672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok. So which ever device is active will assume the role of the active MAC and IP address (All interfaces except failover). So if the active ASA failed, the standby ASA would take over using the active Mac and IP of the Active ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jul 2009 01:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339281#M858672</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2009-07-15T01:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339282#M858673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jul 2009 12:35:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339282#M858673</guid>
      <dc:creator>Todd Pula</dc:creator>
      <dc:date>2009-07-15T12:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339283#M858674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i need to bring this topic back up. Since each ASA will be connected to 2 4506s on the LAN side, i assume i will have an SVI on each 4506 for int vlan 2? Then i'll just include vlan 2 in the trunk between the two 4506s? Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4506_1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 2&lt;/P&gt;&lt;P&gt; name 4506_ASA&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface vlan 2&lt;/P&gt;&lt;P&gt; ip address 10.10.2.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4506_2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 2&lt;/P&gt;&lt;P&gt; name 4506_ASA&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface vlan 2&lt;/P&gt;&lt;P&gt; ip address 10.10.2.3 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then trunk vlan 2 between the 4506s&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Aug 2009 12:17:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339283#M858674</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2009-08-12T12:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339284#M858675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You got it.  VLAN 2 will be defined on both switches.  You may also look into using HSRP on the core 4506s in order to provide for further resiliency.  As for the dedicated failover link, you can either configure it in a similar fashion as above using a dedicated VLAN or you can use an xover connection between the two chassis.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Aug 2009 13:07:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339284#M858675</guid>
      <dc:creator>Todd Pula</dc:creator>
      <dc:date>2009-08-12T13:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339285#M858676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;for failover, i'm using a dedicated layer 2 vlan. I am already running HSRP on a few DC vlans, everything else is P2P links with EIGRP. I wouldn't run HSRP on the vlan 2 SVIs would i? Seems like it would conflict with my ASA failover on the LAN side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Aug 2009 13:13:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby/m-p/1339285#M858676</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2009-08-12T13:13:41Z</dc:date>
    </item>
  </channel>
</rss>

