cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
743
Views
0
Helpful
3
Replies

CIsco 5525x Context - Active Active

Mohammed
Level 1
Level 1

Hi All,

 

We currently have a Cisco 5525x with 10 context, and am looking to put a secondary 5525x as a HA.

 

So both to run both context as active active.

 

The primary ASA is up and running. So what is needed to get the other 5525x which is not configured to join the active active and sync all configure from the primary?

 

Thanks,

1 Accepted Solution

Accepted Solutions

Maykol Rojas
Cisco Employee
Cisco Employee

Hello; 

 

Configure the regular failover on the primary unit. Check which of the contexts will be active in one unit and another (using the failover groups). Once that is done, configure the failover link to the seconary Unit, wait until it replicates and then manually move some of the contexts to the secondary firewall (it is not done automatically unless you have the preempt command). 

 

Here is some documentation about it: 

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/91336-pix-activeactive-config.html

 

Its a bit old but same concept applies, commands, etc. 

 

Mike. 

 

Mike

View solution in original post

3 Replies 3

Maykol Rojas
Cisco Employee
Cisco Employee

Hello; 

 

Configure the regular failover on the primary unit. Check which of the contexts will be active in one unit and another (using the failover groups). Once that is done, configure the failover link to the seconary Unit, wait until it replicates and then manually move some of the contexts to the secondary firewall (it is not done automatically unless you have the preempt command). 

 

Here is some documentation about it: 

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/91336-pix-activeactive-config.html

 

Its a bit old but same concept applies, commands, etc. 

 

Mike. 

 

Mike

Hi Mike,

 

Perfect, Thank you!

Mohammed

Hi Mike,

 

I have one more question.

As the Actice/Active with be multi-context.

Each context has its own inside and outside ip addresses. like Inside interface has sub-interfaces on G0/1 with a private ip and all contexts have their own public on their outside interface which is gi0/0.

Do I need to configure standby IP on all interfaces assigned to all contexts?

Thanks

Mohammed

 

Review Cisco Networking for a $25 gift card