cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
689
Views
0
Helpful
1
Replies

ASA 5585, Active/Active and shared interface design

aacole
Level 5
Level 5

Hi, hopefully a quick question on the use of a pair of ASA 5585's in active/active mode with a shared outside interface.

Last time I did this was with FWSM, there was a restriction where all contexts that share an outside interface have to be in the same failover group.

Does this apply also to the ASA? My thought is that it will, but I am unable to find that in any documentation.

My 5585's will be running 8.4 code.

Andy

1 Reply 1

aacole
Level 5
Level 5

Ha, answered my own question, the reference is in that excellent book by Jazib Frahim and Omar Santos, `Cisco ASA: All in one firewall, IPS and VPN adaptive security appliance' on page 353, knew I read it somewhere!

The contexts sharing an interface need  to be in the same failover group.

Unless anyone knows different.... 

Message was edited by: ANDY COLE

Review Cisco Networking for a $25 gift card