02-28-2018 10:34 AM - edited 02-21-2020 07:27 AM
Right now, module 1 is the IPS and the FW is in Active/Standby failover mode. I need to change the FW to Active/Active failover mode to use both as a primary and secondary FW. I use the Mgmt wizard and enter the default Mgmt Ip of the IPS (192.168.1.2) as the Peer IP Address and receive a "peer connectivity" error.
Both the FW module (192.168.1.1) and the IPS (192.168.1.2) are pingable. Any help??
03-01-2018 02:14 AM
As long as you have a single context ASA you cannot use the Active-Active HA feature.
Active-active is only supported for multiple context ASAs. In that case you designate a given context as active on a given appliance.
Also note that changing from single context to multiple context will wipe out any existing configuration.
03-05-2018 10:53 AM
03-06-2018 02:44 AM
One 5585-X chassis = one firewall. That's true with or without a module in slot 1.
The interfaces on the SSPs can always be used as additional interfaces. That's true whether they are an additional core SSP, IPS SSP, ASA CX SSP or Firepower SSP.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide