03-08-2020 12:26 AM
Hi Team,
Greetings for the day...!!!
I have two below questions for Cisco ASA & Cisco NGFW stateful fail-over.
(1) Stateful fail-over in Cisco ASA also replicates all live entries of VPN (Site-to-Site IPSec and Remote-Access VPN) along with Xlates/Connection table while in failover situation?
(2) Does Cisco NGFW supports stateful fail-over? Can you give me best link to understand Fail-over in Cisco NGFW?
Thanks & Regards,
Bhikshuk Patel
Solved! Go to Solution.
03-08-2020 01:40 AM
sorry here you go
03-08-2020 12:57 AM
(1) Stateful fail-over in Cisco ASA also replicates all live entries of VPN (Site-to-Site IPSec and Remote-Access VPN) along with Xlates/Connection table while in failover situation?
yes that correct.
Stateless failover—The security appliance maintains the connection table but doesnot replicate entries to the standby appliance.
Stateful failover—The security appliance maintains the connection table and repli-cates it to the standby appliance.
In a stateful failover, the active appliance sends an update to the standby unit wheneverthere is a change in the state table. In this mode, the active appliance sends statefulupdates over a dedicated link to the standby unit. When the standby unit becomes active,it does not need to build any connection entries because all the entries already exist in itsdatabase. This dedicated connection is known as thestateful link
.
(2) Does Cisco NGFW supports stateful fail-over? Can you give me best link to understand Fail-over in Cisco NGFW?
yes FTD support the same feature as its unified image of snort and ASA. here
03-08-2020 01:35 AM
Thank you sheraz Salim for very well explanation. However, link given by you is not opening. Can you copy-paste full link over here?
03-08-2020 01:40 AM
sorry here you go
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide