cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
142
Views
0
Helpful
1
Replies
Highlighted
Beginner

ASA standby IP on Tunnel interface

Hello.

 

We are using route based VPN with IKEv2 on VTI interfaces on Cisco ASA, netmask is /30. Now we are planning on to migrate to Active/Failover cluster. Is it necessary to create a standby ip on a Tunnel interface or it will work fine without it? How can it affect failover if there is no standby ip on the Tunnel interface?

1 ACCEPTED SOLUTION

Accepted Solutions
RJI Advisor
Advisor

Re: ASA standby IP on Tunnel interface

Hi,
Only the physical interfaces should require a standby IP address, not the tunnel interface. When failover occurs the VTI will move to the new primary ASA.

HTH

View solution in original post

1 REPLY 1
RJI Advisor
Advisor

Re: ASA standby IP on Tunnel interface

Hi,
Only the physical interfaces should require a standby IP address, not the tunnel interface. When failover occurs the VTI will move to the new primary ASA.

HTH

View solution in original post