<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA A/S failover connection with Switch in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960181#M940920</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;" 1. all the port in the switch in the same vlan " &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct,  if you have say 3 interfaces on each firewall Active/Failover, each must have unique VLAN in the switch. Say, PIX-1-Inside interface VLAN3 , PIX-2-Inside interface must be in VLAN3 and so on  for other interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;" 2. what is the default GW for the webserver ? "  &lt;/P&gt;&lt;P&gt;"3. 2.1 or 2.2 ? " &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to use 192.168.2.1 as your DG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the same link used by Jorge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I quote from link !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Active/Standby Failover Overview&lt;/B&gt; &lt;/P&gt;&lt;P&gt;Active/Standby failover lets you use a standby security appliance to take over the functionality of a failed unit. When the active unit fails, it changes to the standby state while the standby unit changes to the active state. The unit that becomes active assumes the IP addresses (or, for transparent firewall, the management IP address) and MAC addresses of the failed unit and begins passing traffic. The unit that is now in standby state takes over the standby IP addresses and MAC addresses. Because network devices see no change in the MAC to IP address pairing, no ARP entries change or time out anywhere on the network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means the default gateway for your webserver or any host is the ip address of the ASA/PIX physical interface, not the standby IP address you configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Active/Standby scenario, if active fails and standby becomes active  the standby will use the the IP addresses of physical interface you configured in primary PIX/ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My hosts default gateway are the physical interface IP addresses configured in Primary PIX..   same principle for ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Mar 2008 05:18:46 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2008-03-17T05:18:46Z</dc:date>
    <item>
      <title>ASA A/S failover connection with Switch</title>
      <link>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960178#M940914</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;  I want to know how we can connect asa a/s failover from the switch. i have one l3 switch from there i connected 2 asa inside interface for the failover. 1st asa ip is 10.0.0.1 standby ip 10.0.0.2 (2nd asa). &lt;/P&gt;&lt;P&gt;What are the procedure we have to configure in the switches ?&lt;/P&gt;&lt;P&gt;either we have to point on primary asa as well as 2dary asa ?&lt;/P&gt;&lt;P&gt;I got confused would anyone help me out ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:17:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960178#M940914</guid>
      <dc:creator>helponline</dc:creator>
      <dc:date>2019-03-11T12:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA A/S failover connection with Switch</title>
      <link>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960179#M940916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/failover.html#wp1047043" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/failover.html#wp1047043&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Mar 2008 02:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960179#M940916</guid>
      <dc:creator>jojuarez</dc:creator>
      <dc:date>2008-03-16T02:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA A/S failover connection with Switch</title>
      <link>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960180#M940919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply, Could you explain briefly how we can configure the switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As i understood,&lt;/P&gt;&lt;P&gt;1. all the port in the switch in the same vlan &lt;/P&gt;&lt;P&gt;2. what is the default GW for the webserver ?&lt;/P&gt;&lt;P&gt;3. 2.1 or 2.2 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i am wrong please correct me !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Mar 2008 04:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960180#M940919</guid>
      <dc:creator>helponline</dc:creator>
      <dc:date>2008-03-17T04:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA A/S failover connection with Switch</title>
      <link>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960181#M940920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;" 1. all the port in the switch in the same vlan " &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct,  if you have say 3 interfaces on each firewall Active/Failover, each must have unique VLAN in the switch. Say, PIX-1-Inside interface VLAN3 , PIX-2-Inside interface must be in VLAN3 and so on  for other interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;" 2. what is the default GW for the webserver ? "  &lt;/P&gt;&lt;P&gt;"3. 2.1 or 2.2 ? " &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to use 192.168.2.1 as your DG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the same link used by Jorge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I quote from link !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Active/Standby Failover Overview&lt;/B&gt; &lt;/P&gt;&lt;P&gt;Active/Standby failover lets you use a standby security appliance to take over the functionality of a failed unit. When the active unit fails, it changes to the standby state while the standby unit changes to the active state. The unit that becomes active assumes the IP addresses (or, for transparent firewall, the management IP address) and MAC addresses of the failed unit and begins passing traffic. The unit that is now in standby state takes over the standby IP addresses and MAC addresses. Because network devices see no change in the MAC to IP address pairing, no ARP entries change or time out anywhere on the network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means the default gateway for your webserver or any host is the ip address of the ASA/PIX physical interface, not the standby IP address you configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Active/Standby scenario, if active fails and standby becomes active  the standby will use the the IP addresses of physical interface you configured in primary PIX/ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My hosts default gateway are the physical interface IP addresses configured in Primary PIX..   same principle for ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Mar 2008 05:18:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960181#M940920</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-03-17T05:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA A/S failover connection with Switch</title>
      <link>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960182#M940924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's really help full..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Mar 2008 06:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-a-s-failover-connection-with-switch/m-p/960182#M940924</guid>
      <dc:creator>helponline</dc:creator>
      <dc:date>2008-03-17T06:10:19Z</dc:date>
    </item>
  </channel>
</rss>

