cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2399
Views
0
Helpful
1
Replies

ASA standby IP on Tunnel interface

ichernyshkov
Level 1
Level 1

Hello.

 

We are using route based VPN with IKEv2 on VTI interfaces on Cisco ASA, netmask is /30. Now we are planning on to migrate to Active/Failover cluster. Is it necessary to create a standby ip on a Tunnel interface or it will work fine without it? How can it affect failover if there is no standby ip on the Tunnel interface?

1 Accepted Solution

Accepted Solutions

Hi,
Only the physical interfaces should require a standby IP address, not the tunnel interface. When failover occurs the VTI will move to the new primary ASA.

HTH

View solution in original post

1 Reply 1

Hi,
Only the physical interfaces should require a standby IP address, not the tunnel interface. When failover occurs the VTI will move to the new primary ASA.

HTH
Review Cisco Networking for a $25 gift card