<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: standby ip addresses? are they necessary on all monitored in in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239719#M920758</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the reply, I've looked into the attached configuration guide; However, in this setup I have each ASA connecting to a different switch on the core switch fabric and additionally, I have used cross-cable connections for both the LAN failover and the State failover link. For the ASAs to lose communication to each other would involve taking down the 3 links? right - 2 of which have no device that can be affected by power?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 May 2013 12:09:00 GMT</pubDate>
    <dc:creator>bernard macharia</dc:creator>
    <dc:date>2013-05-24T12:09:00Z</dc:date>
    <item>
      <title>standby ip addresses? are they necessary on all monitored interfaces for failover</title>
      <link>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239717#M920756</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need clarification on an interesting issue that I have observed while configuring an Active/Standby setup for using 2 x cisco 5525x with version 8.6;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the setup, we have 4 subnets that we need to keep separate. I have connected each of the ASAs to the different subnets. However, only 1 subnet has standby ip address configured while all the other subnets only have an active address on the active firewall. As this is a failover scenario, I have 2 interfaces for both LAN and stateful failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just tested the failover on 2 of the subnets without any standby ip address and to my surprise all seems to be working as expected. Just need clarification on why we need standby addresses on the monitored interfaces when clearly the setup can work without any configured. Are there any implications with proceeding without the standby ip addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239717#M920756</guid>
      <dc:creator>bernard macharia</dc:creator>
      <dc:date>2020-02-21T12:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: standby ip addresses? are they necessary on all monitored in</title>
      <link>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239718#M920757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How did you test failover? Just with unplugging the interfaces? That can be easily recognized without the standby IPs. But if you have an indirect problem (e.g. ASA1 connected to switch1, ASA2 connected to switch2 and the link between the switches fail), then the ASAs need their "hello-protocol" and testing on the interfaces which can only be used if you configured the primary and the standby IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You find more info on that in the config-guide:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_overview.html#wp1079010"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_overview.html#wp1079010&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 11:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239718#M920757</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-05-24T11:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: standby ip addresses? are they necessary on all monitored in</title>
      <link>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239719#M920758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the reply, I've looked into the attached configuration guide; However, in this setup I have each ASA connecting to a different switch on the core switch fabric and additionally, I have used cross-cable connections for both the LAN failover and the State failover link. For the ASAs to lose communication to each other would involve taking down the 3 links? right - 2 of which have no device that can be affected by power?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 12:09:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239719#M920758</guid>
      <dc:creator>bernard macharia</dc:creator>
      <dc:date>2013-05-24T12:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: standby ip addresses? are they necessary on all monitored in</title>
      <link>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239720#M920759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Especially in your setup there can be happening much that can't be recognized by the ASA without a proper failover setup. That could be a mafunctioning port in your infrastructure for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But lets aproach it the other way round: What benefit do you see in setting it up in a non-standard way? Or what kind of problems do you expect? Typically the standby IP is only not configured if there is no IP available for example on the outside-interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 17:08:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239720#M920759</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-05-24T17:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: standby ip addresses? are they necessary on all monitored in</title>
      <link>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239721#M920760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies Karsten.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree when you phrase it that way - there's no benefit in setting it up in a non-standard way - ultimately it's the recommended best practise; only issue is that the client didnt want to allocate an ip address if there was no need to. I appreciate the help in explaining the implications and will try to get this done as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 11:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/standby-ip-addresses-are-they-necessary-on-all-monitored/m-p/2239721#M920760</guid>
      <dc:creator>bernard macharia</dc:creator>
      <dc:date>2013-08-02T11:37:34Z</dc:date>
    </item>
  </channel>
</rss>

