cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
462
Views
0
Helpful
3
Replies

ASA5500 HA

mohammedrafiq
Level 1
Level 1

Hi,

We will like to achive HA between two datacentres.Please see an attached topology diagram.Our ASA will be connected through Pair of Nexus, and if the WAN link broke between two datacentres, how will ASA will detect the failure because local link between ASA and local swich will be always up.

Regards,

3 Replies 3

sean_evershed
Level 7
Level 7

Hi, Do you mean an active/standby failover pair of ASAs? If so this topology may not work since the recommnedation is that they should have a LAN based failover connection. See the reference below:

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1051745

The failover link for the two firewalls should also be on the same VLAN.

Hi Sean,

I forgot to mention that both links betwwen datacentres are layer2, and we can extend VLAN.

Regards,

Hi Mohammed,

In addition to monitoring the state of the interface (i.e. up or down), ASAs in a failover pair also exchange hello messages. Therefore, even though the link to the local switch is up, the mate will never receive the hello packet and the unit who sent it will never receive a response. This exchange is how the ASAs know they've been cut off from their mate.

This link contains more details about how the ASAs do their health monitoring:

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_overview.html#wp1079010

You may also want to review the recommended scenarios for connecting the failover links:

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ha_overview.html#wp1096444

Hope that helps.

-Mike

Review Cisco Networking for a $25 gift card