cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1718
Views
0
Helpful
4
Replies

ASA 5506X failover with object tracking

haintnsl
Level 1
Level 1

Dear all,

I am doing installation a network infrastructure as the attached picture. Our purpose is to track a status (working or goes down) of the border router (ISR4321-R1)  or remote connection between ISR4321-R1 and KOR-RT1 (up or down). In case one of these conditions occurs, the active firewall (ASA5506-FW1) will be standby and then the standby (ASA5506-FW2) will take over. I don't know how to do it. Is there any solution for this requirement?

 

Thank you all very much!

 

 

1 Accepted Solution

Accepted Solutions

Sorry, I can't help.  I don't have the time or the resource (lab) to explore such a request.  Not sure the reasoning behind failovering to standby firewall during your described scenarios.  For simplicity, I would use routing protocol for network resiliency when either R1 and/or KOR-R1 becomes unresponsive.  Maybe a community member has done something similar to yours and willing to share.  

View solution in original post

4 Replies 4

joseph.h.nguyen
Level 1
Level 1

Have you considered using HA on your two ASA's?  It makes firewall administration more efficient and removing the SLA tracking requirement but you may have to configure OSPF to react to sudden routing convergence.

 

To answer your question, you may find an idea matching your intended purpose, see link: https://community.cisco.com/t5/firewalls/asa-sla-tracking-w-multiple-icmp-checks/td-p/1368366

 

Hi Joseph,

Thank you so much for your advice!

Actually, I setup HA for the firewall (Active-Stanby). I'd like to track the status of the border router (R1) and the remote connection (to KOR-R1). ASA5506-FW2 (in stanby mode) will take over the primary when one of above conditions occur. 

Could you please advise me?

Thank you so much!

Sorry, I can't help.  I don't have the time or the resource (lab) to explore such a request.  Not sure the reasoning behind failovering to standby firewall during your described scenarios.  For simplicity, I would use routing protocol for network resiliency when either R1 and/or KOR-R1 becomes unresponsive.  Maybe a community member has done something similar to yours and willing to share.  

Hi Joseph,

 

Thank you very much for your help!

 

BRs,

HaiNT

Review Cisco Networking for a $25 gift card