cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
658
Views
0
Helpful
3
Replies

ASA-5525 with sfr module Failover

sifathmirza
Beginner
Beginner

 Hi all,

I have ASA-5525  with sfr module running as active/standby, sfr is managed by ASDM.
1. Can i take both sfr modules ip address as same or different ? (managed by ASDM) (i guess same)
2. If iam using firepower management center then how can i take ip addree for sfr ? same or different. (i guess different)
3. can i use firepower in context mode.

1 Accepted Solution

Accepted Solutions

nspasov
Cisco Employee
Cisco Employee

Hi there! My answers below:

1. No, each SFR module needs to have its own unique IP address. The SFR modules do not understand the concept of active/standby. They are independent and as a result, each module needs to be licensed and configured. Thus, it is important that the configurations that you are pushing to the SFR modules are identical. 

2. The same as #1. Each SFR module will have its own IP address

3. Yes, multi-context mode is supported. However, the actual SFR modules are not/cannot be split into different contexts. The modules are shared between all of the contexts and separate sfr policies can be applied to different contexts.

I hope this helps!

Thank you for rating helpful posts!

View solution in original post

3 Replies 3

nspasov
Cisco Employee
Cisco Employee

Hi there! My answers below:

1. No, each SFR module needs to have its own unique IP address. The SFR modules do not understand the concept of active/standby. They are independent and as a result, each module needs to be licensed and configured. Thus, it is important that the configurations that you are pushing to the SFR modules are identical. 

2. The same as #1. Each SFR module will have its own IP address

3. Yes, multi-context mode is supported. However, the actual SFR modules are not/cannot be split into different contexts. The modules are shared between all of the contexts and separate sfr policies can be applied to different contexts.

I hope this helps!

Thank you for rating helpful posts!

Hi Nspasov,

On the same line , if one ASA 5515/25 have SFR module installed and another ASA is missing that module, Can these ASA still form failover/HA  ?

If not, if we disable /remove sfr (hope that is possible)---can we configure fail-over with out issues ?

 

 

 

Marvin Rhoads
Hall of Fame Community Legend Hall of Fame Community Legend
Hall of Fame Community Legend

@ABhamra this thread is almost 6 years old and @nspasov has left Cisco. (Hi Neno!)

You can form a HA pair with devices as you describe if you simply uninstall the sfr software module on the ASA that currently has it.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers