cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1521
Views
0
Helpful
4
Replies

ASA 5525 failover

Maurice Ball
Level 3
Level 3

I need to setup an ASA 5525 in Active/Standby failover mode. I am setting up the ASA for a company that purchased only one public IP address. The public IP address is assigned to the outside interface. My question is will failover work correctly if I don't use a secondary IP address on the failover configuration on the outside interface?

1 Accepted Solution

Accepted Solutions

Yes, it monitors the interface using the interface IP Address and when it detects no link on that interface, it will declare that the peer is down. If you don't have an ip address on the standby unit, it won't be able to check that it is UP to start with, hence won't be monitored or it will always declare that its peer is down.

View solution in original post

4 Replies 4

Jennifer Halim
Cisco Employee
Cisco Employee

You can still configure failover and monitor other interfaces but the outside interface since there is no ip address assigned as the secondary failover IP.

However if the outside interface fail, it will not be detected by the ASA failover feature.

Are you saying even if I disconnect the ethernet cable that is connected to the primary ASA outside interface, the primary ASA still will not failover to the secondary ASA because I did not have a secondary IP address on the outside interface?

Yes, it monitors the interface using the interface IP Address and when it detects no link on that interface, it will declare that the peer is down. If you don't have an ip address on the standby unit, it won't be able to check that it is UP to start with, hence won't be monitored or it will always declare that its peer is down.

thanks

Review Cisco Networking for a $25 gift card