12-19-2010 04:15 PM - edited 03-11-2019 12:24 PM
What are the advantages/disadvantages of configuring Active/Active vs Active/Standby Failover for Cisco ASA 5510?
Which one should be preferred over the other?
What's the Best Practice followed when configuring failover?
-NG
12-19-2010 04:26 PM
Active/Standby failover works in both single mode or multiple context mode. It provides hot standby and replicates all the stateful information from active to standby firewall.
Active/Active failover only works in multiple context mode. Example: if you have 5 context, you can have 2 active on the primary firewall, and 3 active on the secondary firewall. When primary firewall fails, the 2 context who was active on the primary firewall will failover to the secondary firewall. After failover, the secondary firewall will have 5 active context.
Hope that helps.
12-19-2010 04:41 PM
We have Checkpoint Firewall and being new to Cisco ASA may I ask this question - what is a context mode?
12-19-2010 05:50 PM
Context is virtual firewall. So within 1 physical ASA firewall you can create multiple virtual firewalls.
Here is a sample configuration for multiple context that would help you to understand the concept better:
12-08-2015 03:21 AM
Hi Jennifer, please suggest that will the firewalls (ASA 5585) in Active/Standby failover with multiple context support SSL VPN. Because I had to know from somewhere that with Active/Active firewalls mode we cannot go with SSL VPN.
12-08-2015 04:41 AM
In order to run Active/Active you need to run "multiple contexts". When you enable "multiple mode" you lose certain functionality. Remote access VPN is one of them.
12-08-2015 05:05 AM
thanks for replying,
tell me one thing if i go for Active/Standby failover that works in both single mode or multiple context mode
so then Remote Access VPN will work only in single mode or in both modes...
12-08-2015 05:53 AM
Remote access VPN only works in "single mode"
12-09-2015 10:29 PM
hi andre,
there is anyway to achieve load balancing with active/standby mode in ASA 5585... I am really worried about that , I have to do load balancing and remote access SSL VPN...
12-10-2015 12:09 AM
Hi. Unfortunately I don't think that's going to work. There is a VPN clustering feature in Version 9.0 but not for Firewall traffic.
04-05-2016 11:23 PM
Hello,
can someone share me the advantages and disadvantages of Active/Active and Active/Passive modes of ASA-5585... better if you a document..
thanks in advance
04-05-2016 11:23 PM
Hello,
can someone share me the advantages and disadvantages of Active/Active and Active/Passive modes of ASA-5585... better if you a document..
thanks in advanc
11-07-2017 11:59 PM
Thanks.
12-15-2017 01:11 AM
Hi Jennifer,
I was just following up on your response as I have a similar query about the active/active v active/standby licence on ASA5510 as both seem to be available (optional) with a Security Plus licence but Active/Active seems to be the default. How can this be changed to an Active/Standby setup because when I try to install Anyconnect licences it states that the failover will be disabled. We do not require multiple contexts so the Active/Standby setup would work fine.
Carl
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide