cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
437
Views
10
Helpful
4
Replies

ASA Active/Active Question

brian.stamper
Level 1
Level 1

My question goes into the VPN world. I've read when in active/active config the ASA's do not support vpn/ipsec tunnel failover. My question is does it support IPSEC/VPN's at all in active/active? I mean i realize they may not failover but if I don't care if they are down can i terminate them to 1 or is it just not possible to use VPN/IPSEC with an ASA active/active setup? Hope this helps.

4 Replies 4

sebastan_bach
Level 4
Level 4

hi sorry vpn cannot be configured on the active/active setup. it does not support for vpns on failover setup u need to configure active/standy.

regards

sebastan

Hi Guys,

In active / standby mode, would I use the track command to set up the 2nd [failover] vpn tunnel? I'm assuming the 2nd ISP would plug into another VLAN port on the ASA and once tracking failed, a new tunnel would be negotiated. Yes?

ddidier
Level 1
Level 1

I believe that version 8.x of the ASA supports Active/Active VPN failover. I looked quickly and couldn't find the notes on this, but I know that this is something I asked about in the past and was told 8.x will support this.

Dan

VPN's are still unsupported in multiple context mode in 8.x.

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/contexts.html

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card