cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5609
Views
5
Helpful
15
Replies

ASA lan-based stateful failover question

cisco24x7
Level 6
Level 6

I have a pair of ASA 5510 with security plus license. I am going to setup site-2-site VPN on them in Active/Stanby configuration STATEFUL failover. I WILL NOT BE USING ANY 802.1Q. I will be running ASA 8.2.1 code.

The ASA5510 comes with 5 interfaces. I have a requirements to have outside, inside, dmz1 and dmz2. However, upon reading this document, I think it stated that I need to have two NICs, one for the failover interface and one for the state interface. If that is the case, that will leave me with only three interfaces.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml#ACT

Is it possible to combine both the state and failover interface into a single physical interface? I remembered I had done it once three years with Pix firewall and even though does not recommend it, it can be done.

Can it be done on ASA with LAN-based failover with combining both failover and state

into a single interface? If so how?

Thanks in advance.

15 Replies 15

happy all working...

Review Cisco Networking for a $25 gift card