11-19-2010 03:23 AM - edited 03-11-2019 12:11 PM
Hi,
Reading through the documentation recommendations and I would like to configure the following setup http://www.cisco.com/en/US/docs/security/asa/asa83/asdm63/configuration_guide/ha_overview.html#wp1095702 scenario 4, figure 58-6 but I can't find specifically details on how to configure the standby redundant failover connection.
Is the stateful failover interface being specified as a different interface to the LAN failover interface the same as a redundant failover line as detailed in figure 58-6?
Thanks,
David.
11-19-2010 06:51 AM
Ok,
I figured out how that we needed to configure a pair of redundant interfaces and then setup the failover using the redundant interface.
I have tested with both cross over cables for the connectivity between the interfaces and straight through cables with a switch. The configuration of both firewalls syncs up, the failover works if one of the interfaces on the primary fails, and both interfaces can ping each other from the redundant interface named failover.
Cheers,
David.
11-19-2010 09:44 AM
It is not required to use a redundant interface for failover.
You can use the failover and the state interface being the same physical interface, you can use seperate one, you can also use redundant interfaces. They will all work.
I hope it clarifies it. a little.
PK
11-19-2010 11:27 AM
David,
What ASDM version are you using? This may be an issue with ASDM.
Gather the "sh fail" status from both untis and make sure the output is what you expect.
Primary shows - This unit active other unit standby ready
secondary shows - This unit standby ready other unit active
Or vice versa.
If this status shows all good, then the issue is mostly likely with the ASDM image you are running.
-KS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide