<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA failover help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-help/m-p/984758#M918983</link>
    <description>&lt;P&gt;Dear all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have 2 ASAs 5520 , they have VPN plus license . i tried to configure them to support failover feature for the customer network. But when configuring the secondary unit with the faiover configuration and enable the faiover on it , it prompts me that it cannot take the configuarion from the primary device due to something in the license (webvpn peers).The following is "show version" output from the two devices :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Primary-ASA# sh ver&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 7.2(3) &lt;/P&gt;&lt;P&gt;Device Manager Version 5.2(3)&lt;/P&gt;&lt;P&gt;Compiled on Wed 15-Aug-07 16:08 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa723-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;ciscoasa up 5 mins 7 secs&lt;/P&gt;&lt;P&gt;Hardware:   ASA5520, 512 MB RAM, CPU Pentium 4 Celeron 2000 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 256MB&lt;/P&gt;&lt;P&gt;BIOS Flash M50FW080 @ 0xffe00000, 1024KB&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             Boot microcode   : CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.04&lt;/P&gt;&lt;P&gt;0: Ext: GigabitEthernet0/0  : address is 001d.459f.ccc6, irq 9&lt;/P&gt;&lt;P&gt;1: Ext: GigabitEthernet0/1  : address is 001d.459f.ccc7, irq 9&lt;/P&gt;&lt;P&gt;2: Ext: GigabitEthernet0/2  : address is 001d.459f.ccc8, irq 9&lt;/P&gt;&lt;P&gt;3: Ext: GigabitEthernet0/3  : address is 001d.459f.ccc9, irq 9&lt;/P&gt;&lt;P&gt;4: Ext: Management0/0       : address is 001d.459f.ccc5, irq 11&lt;/P&gt;&lt;P&gt;5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11&lt;/P&gt;&lt;P&gt;6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 5&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : Unlimited &lt;/P&gt;&lt;P&gt;Maximum VLANs               : 150       &lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited &lt;/P&gt;&lt;P&gt;Failover                    : Active/Active&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled   &lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled   &lt;/P&gt;&lt;P&gt;Security Contexts           : 2         &lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled  &lt;/P&gt;&lt;P&gt;VPN Peers                   : 750       &lt;/P&gt;&lt;P&gt;WebVPN Peers                : 2         &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has an ASA 5520 VPN Plus license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondary-ASA# sh ver&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 7.2(3) &lt;/P&gt;&lt;P&gt;Device Manager Version 5.2(3)&lt;/P&gt;&lt;P&gt;Compiled on Wed 15-Aug-07 16:08 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa723-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;ciscoasa up 6 mins 47 secs&lt;/P&gt;&lt;P&gt;Hardware:   ASA5520, 512 MB RAM, CPU Pentium 4 Celeron 2000 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 256MB&lt;/P&gt;&lt;P&gt;BIOS Flash LHF00L47 @ 0xffe00000, 1024KB&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)&lt;/P&gt;&lt;P&gt;                             Boot microcode   : CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.04&lt;/P&gt;&lt;P&gt;0: Ext: GigabitEthernet0/0  : address is 001b.d554.6c04, irq 9&lt;/P&gt;&lt;P&gt;1: Ext: GigabitEthernet0/1  : address is 001b.d554.6c05, irq 9&lt;/P&gt;&lt;P&gt;2: Ext: GigabitEthernet0/2  : address is 001b.d554.6c06, irq 9&lt;/P&gt;&lt;P&gt;3: Ext: GigabitEthernet0/3  : address is 001b.d554.6c07, irq 9&lt;/P&gt;&lt;P&gt;4: Ext: Management0/0       : address is 001b.d554.6c03, irq 11&lt;/P&gt;&lt;P&gt;5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11&lt;/P&gt;&lt;P&gt;6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq &lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : Unlimited &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maximum VLANs               : 150       &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failover                    : Active/Active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security Contexts           : 2         &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN Peers                   : 750       &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WebVPN Peers                : 25        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has an ASA 5520 VPN Plus license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the license that i need to enable the failover feature on the above devices???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;waiting your replies&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:54:51 GMT</pubDate>
    <dc:creator>mohamed_makled</dc:creator>
    <dc:date>2019-03-11T12:54:51Z</dc:date>
    <item>
      <title>ASA failover help</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-help/m-p/984758#M918983</link>
      <description>&lt;P&gt;Dear all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have 2 ASAs 5520 , they have VPN plus license . i tried to configure them to support failover feature for the customer network. But when configuring the secondary unit with the faiover configuration and enable the faiover on it , it prompts me that it cannot take the configuarion from the primary device due to something in the license (webvpn peers).The following is "show version" output from the two devices :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Primary-ASA# sh ver&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 7.2(3) &lt;/P&gt;&lt;P&gt;Device Manager Version 5.2(3)&lt;/P&gt;&lt;P&gt;Compiled on Wed 15-Aug-07 16:08 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa723-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;ciscoasa up 5 mins 7 secs&lt;/P&gt;&lt;P&gt;Hardware:   ASA5520, 512 MB RAM, CPU Pentium 4 Celeron 2000 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 256MB&lt;/P&gt;&lt;P&gt;BIOS Flash M50FW080 @ 0xffe00000, 1024KB&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             Boot microcode   : CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.04&lt;/P&gt;&lt;P&gt;0: Ext: GigabitEthernet0/0  : address is 001d.459f.ccc6, irq 9&lt;/P&gt;&lt;P&gt;1: Ext: GigabitEthernet0/1  : address is 001d.459f.ccc7, irq 9&lt;/P&gt;&lt;P&gt;2: Ext: GigabitEthernet0/2  : address is 001d.459f.ccc8, irq 9&lt;/P&gt;&lt;P&gt;3: Ext: GigabitEthernet0/3  : address is 001d.459f.ccc9, irq 9&lt;/P&gt;&lt;P&gt;4: Ext: Management0/0       : address is 001d.459f.ccc5, irq 11&lt;/P&gt;&lt;P&gt;5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11&lt;/P&gt;&lt;P&gt;6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 5&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : Unlimited &lt;/P&gt;&lt;P&gt;Maximum VLANs               : 150       &lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited &lt;/P&gt;&lt;P&gt;Failover                    : Active/Active&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled   &lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled   &lt;/P&gt;&lt;P&gt;Security Contexts           : 2         &lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled  &lt;/P&gt;&lt;P&gt;VPN Peers                   : 750       &lt;/P&gt;&lt;P&gt;WebVPN Peers                : 2         &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has an ASA 5520 VPN Plus license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondary-ASA# sh ver&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 7.2(3) &lt;/P&gt;&lt;P&gt;Device Manager Version 5.2(3)&lt;/P&gt;&lt;P&gt;Compiled on Wed 15-Aug-07 16:08 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa723-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;ciscoasa up 6 mins 47 secs&lt;/P&gt;&lt;P&gt;Hardware:   ASA5520, 512 MB RAM, CPU Pentium 4 Celeron 2000 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 256MB&lt;/P&gt;&lt;P&gt;BIOS Flash LHF00L47 @ 0xffe00000, 1024KB&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)&lt;/P&gt;&lt;P&gt;                             Boot microcode   : CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.04&lt;/P&gt;&lt;P&gt;0: Ext: GigabitEthernet0/0  : address is 001b.d554.6c04, irq 9&lt;/P&gt;&lt;P&gt;1: Ext: GigabitEthernet0/1  : address is 001b.d554.6c05, irq 9&lt;/P&gt;&lt;P&gt;2: Ext: GigabitEthernet0/2  : address is 001b.d554.6c06, irq 9&lt;/P&gt;&lt;P&gt;3: Ext: GigabitEthernet0/3  : address is 001b.d554.6c07, irq 9&lt;/P&gt;&lt;P&gt;4: Ext: Management0/0       : address is 001b.d554.6c03, irq 11&lt;/P&gt;&lt;P&gt;5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11&lt;/P&gt;&lt;P&gt;6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq &lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : Unlimited &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maximum VLANs               : 150       &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failover                    : Active/Active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security Contexts           : 2         &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN Peers                   : 750       &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WebVPN Peers                : 25        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has an ASA 5520 VPN Plus license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the license that i need to enable the failover feature on the above devices???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;waiting your replies&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-help/m-p/984758#M918983</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2019-03-11T12:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover help</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-help/m-p/984759#M918984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe because there is a mismatch in the WebVPN licenses of the two boxes. One has a 25 user license installed, whereas the other has the default free users (two).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jun 2008 01:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-help/m-p/984759#M918984</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-04T01:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover help</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-help/m-p/984760#M918985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply , what i can do to solve this issue? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA that has few webvpn peers needs another license or not???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jun 2008 05:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-help/m-p/984760#M918985</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2008-06-04T05:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover help</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-help/m-p/984761#M918986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I could only locate the following on the Cisco Website:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Both units have the same hardware, software configuration, and *proper* license."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be best to approach your local SE or if you work for a Cisco Partner, the Partner Online pre-sales help Team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jun 2008 05:56:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-help/m-p/984761#M918986</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-04T05:56:06Z</dc:date>
    </item>
  </channel>
</rss>

