cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
938
Views
0
Helpful
3
Replies

ASA-5525 with sfr module Failover

sifathmirza
Level 1
Level 1

 Hi all,

I have ASA-5525  with sfr module running as active/standby, sfr is managed by ASDM.
1. Can i take both sfr modules ip address as same or different ? (managed by ASDM) (i guess same)
2. If iam using firepower management center then how can i take ip addree for sfr ? same or different. (i guess different)
3. can i use firepower in context mode.

1 Accepted Solution

Accepted Solutions

nspasov
Cisco Employee
Cisco Employee

Hi there! My answers below:

1. No, each SFR module needs to have its own unique IP address. The SFR modules do not understand the concept of active/standby. They are independent and as a result, each module needs to be licensed and configured. Thus, it is important that the configurations that you are pushing to the SFR modules are identical. 

2. The same as #1. Each SFR module will have its own IP address

3. Yes, multi-context mode is supported. However, the actual SFR modules are not/cannot be split into different contexts. The modules are shared between all of the contexts and separate sfr policies can be applied to different contexts.

I hope this helps!

Thank you for rating helpful posts!

View solution in original post

3 Replies 3

nspasov
Cisco Employee
Cisco Employee

Hi there! My answers below:

1. No, each SFR module needs to have its own unique IP address. The SFR modules do not understand the concept of active/standby. They are independent and as a result, each module needs to be licensed and configured. Thus, it is important that the configurations that you are pushing to the SFR modules are identical. 

2. The same as #1. Each SFR module will have its own IP address

3. Yes, multi-context mode is supported. However, the actual SFR modules are not/cannot be split into different contexts. The modules are shared between all of the contexts and separate sfr policies can be applied to different contexts.

I hope this helps!

Thank you for rating helpful posts!

Hi Nspasov,

On the same line , if one ASA 5515/25 have SFR module installed and another ASA is missing that module, Can these ASA still form failover/HA  ?

If not, if we disable /remove sfr (hope that is possible)---can we configure fail-over with out issues ?

 

 

 

@ABhamra this thread is almost 6 years old and @nspasov has left Cisco. (Hi Neno!)

You can form a HA pair with devices as you describe if you simply uninstall the sfr software module on the ASA that currently has it.

Review Cisco Networking for a $25 gift card