02-22-2019 07:43 AM - edited 02-21-2020 08:51 AM
hi,
i'm going to migrate a standalone ASA5520 Context FW to a ASA5525-x HA.
my question is, can i configure the ASA5525-X context with just a single 'outside' IP? this is due to broken or discontiguous IP assignment.
will failover work to the secondary 5525-X FW even without the standby outside IP?
Solved! Go to Solution.
02-22-2019 09:32 AM - edited 02-22-2019 09:33 AM
You don't need to get two IP address to make HA work.
# interface gi0/0
# nameif inside
# ip address <primary ip> standby <secondary ip>
The primary ASA always use the primary IP address, when it fail-over to another ASA, it will pick up the primary IP.
The secondary IP is for you to access the standby unit, have no special function on control plane / data plane.
That's mean, the following configuration should also work well.
# interface gi0/0
# nameif inside
# ip address <primary ip>
02-22-2019 09:32 AM - edited 02-22-2019 09:33 AM
You don't need to get two IP address to make HA work.
# interface gi0/0
# nameif inside
# ip address <primary ip> standby <secondary ip>
The primary ASA always use the primary IP address, when it fail-over to another ASA, it will pick up the primary IP.
The secondary IP is for you to access the standby unit, have no special function on control plane / data plane.
That's mean, the following configuration should also work well.
# interface gi0/0
# nameif inside
# ip address <primary ip>
02-22-2019 09:36 AM
02-22-2019 11:44 AM
I did testing just now, that should work like others said. i gives warning but everything should be fine.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: