03-16-2022 01:24 AM - edited 03-16-2022 01:25 AM
I have 2 asas. ASA-A and ASA-B. I want to configure ASA-B as an active unit and ASA-A as an standby unit. Could any one tell me how could i do that? IS there any election process will happen for selecting active/standby units between asa?
Solved! Go to Solution.
03-16-2022 01:28 AM
The config guide has details on setting up HA.
The first one that is up will take the Active role and the second will be Standby. There's no election process per se other than checking if the unit is healthy. Assuming both units are healthy, whichever is active will stay that way until the admin changes it manually of the unit becomes unhealthy.
03-16-2022 01:28 AM
The config guide has details on setting up HA.
The first one that is up will take the Active role and the second will be Standby. There's no election process per se other than checking if the unit is healthy. Assuming both units are healthy, whichever is active will stay that way until the admin changes it manually of the unit becomes unhealthy.
03-16-2022 01:49 AM
Below is active/standby guide
For Active/Active
other Document is below for Active/standby
https://www.thegeekstuff.com/2011/09/cisco-asa-high-availability/
Those documents will help you to understand step by step config.
Thanks,
Jitendra
03-16-2022 02:21 AM
By default ASA is in secondary mode.
for ASA-B to be active(primary) here is the config
ASA-B failover lan unit primary interface gigabitEthernet 0/3 no shutdown ! failover lan interface LANFAIL gigabitethernet 0/3 failover interfaces ip LANFAIL x.x.x.x 255.255.255.0 standby x.x.x.y failover link LANFAIL exit
once ASA-B is configured as Primary (Active) as soon as you configured the ASA-A as standby (Secondary) all the configuration from the ASA-B (which is primary active) will replicate to secondary ASA-A.
ASA-A failover lan unit secondary interface gigabitEthernet 0/3 no shutdown ! failover lan interface LANFAIL gigabitethernet 0/3 failover interfaces ip LANFAIL x.x.x.x 255.255.255.0 standby x.x.x.y failover link LANFAIL exit
few command to check if the ASA failover is working
show failover | i host show failover detail
once failover is working you can configure the active and standby ip interfaces on you data interfaces and also monitoring on the interface. If you have sub-interface on your firewall they need to be configured as monitoring as sub-interface by default are not in monitoring.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: