09-08-2015 07:58 AM - edited 03-11-2019 11:34 PM
Hi As we know, failover has special ip address to connect primary asa and second asa. For example 1.1.1.1 and 1.1.1.2. Do you think that other device or other failover asa can use the 1.1.1.1 and 1.1.1.2 in the local network ? Thank you.
Solved! Go to Solution.
09-08-2015 08:02 AM
Yes, definetly. As this network is not gonna be routed.
In other words, this network in not to be reached by anyone else. So it should be definetly allowed in another pair of failover.
HTH
Regards,
Salman
09-08-2015 08:02 AM
Yes, definetly. As this network is not gonna be routed.
In other words, this network in not to be reached by anyone else. So it should be definetly allowed in another pair of failover.
HTH
Regards,
Salman
09-08-2015 08:24 AM
Thank you for your reply. Usually we do not route that ip address. That should not be a problem. Let us suppose the topology is like this : asa2--asa1-----asa3--asa4. here are two pair of failover, one is asa2 and asa1. second is asa3 and asa4. if they have the same ip address for failover link, do you think it would be ok ?
09-08-2015 08:42 AM
I don't think its gonna be a problem by using same network between ASA2,ASA1 and ASA3,ASA4.
Consider ASA2(1.0.0.1)--------(1.0.0.2)ASA1
Let MAC of ASA2 be 222 and ASA1 be 111
Now coming to ASA3 (1.0.0.1)--------(1.0.0.2)ASA4
Let MAC of ASA3 be 333 and ASA4 be 444
whenever the data has to be moved to 1.0.0.2 by ASA2 it would forward it to 111
whenever the data has to be moved to 1.0.0.2 by ASA3 it would forward it to 444
for ASA2 and ASA1 the only 1.0.0.0 network will be between them and same for ASA3 and ASA4 will think 1.0.0.0 in only in between themselves.
I will try making a tolopogy in gns3 tomm to explain it better :)
Regards,
Salman
Note: Just joined the support forum, didnt know it would be so much fun!!! :D :D
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide