A question about the part number for an ASA5525-X failover unit
I am looking at purchasing two ASA5525-X firewalls to be used as a failover pair. In the past (a LONG time ago) I seem to recall that there was a different part number for the firewall that was going to be used as the failover unit. I have not been able to find anything like that for the 5525-X. The primary unit would be a ASA5525-IPS-K9, since I want to take advantage of the IPS functionality. Would I need to purchase an identical ASA5525-IPS-K9 to be used as the failover unit, or is there a different part number I should use? I've found several documents online that state that the failover unit inherits the licensed features of the primary unit (for 30 days after the primary unit's failure) but nothing about the part numbers for the original hardware purchase.
For the 5525-X, you would use identical part numbers. Each would need an associated Smartnet support contract for their respective IPS modules' subscription-based definitions to update properly. All the other licensing on the Primary - Active unit would convey to the Secondary - Standby in an HA configuration.
Although you didn't ask, if you had the 5512-X entry level model (or older 5505 or 5510) each would need to be ordered with Security Plus licensing to build an HA pair.
I would recommend considering either the FirePOWER or CX module IPS vs the one you mentioned. The ASA5525-IPS-K9 is the legacy Cisco IPS technology that's gradually being phased out in favor of the newer type. While it is indeed still sold, we are encouraging customers to consider adopting the Next Generation Firewall IPS type vs the older one as it covers a more comprehensive threat spectrum.
Hi Guys, I have two questions about EIGRP behavior when we have Multiple EIGRP routes: 1- I tried to show on some router the acquired EIGRP paths for a route X.X.X.X by typing the command : "show ip eigrp topology X.X.X.X". On the output there w...
[ The Discussion forum will be published on December 1st ]
Take the opportunity to reach out to our expert and discuss best practices regarding on how to troubleshoot a live network and identify the root cause easily. Learn more about Serviceability and h...
To provide a solution to quickly setup a router at a remote location that supports WiFi and provides instant internet access using LTE as a transport while deploying with Cisco SD-WAN.
Plug the router to a power sou...
Hello!I'm looking for a way to make my EEM script more dynamic and automated for my environment. This is what I have - basically I just capture the 4 IPSec peer IP addresses of each neighbor and insert this data into 4 different variables. ...
Hi all,I have a couple of Nexus9k switches. I need to get tcpdump from the physical interface which connected to the server. I'm looking for a specific protocol on tcpdump so that which feature should I use? I asked that because I couldn't full...