02-18-2016 03:30 AM - edited 03-12-2019 12:19 AM
Hi,
Can you share the failover configuration for ASA firewall. Incase if any of the interface on primary(active) firewall fails it should switch over to secondary(standby) host.
02-18-2016 04:45 AM
Full configuration with stateful failover.
PRIMARY
failover
failover lan unit primary
failover lan interface folink GigabitEthernet0/6
failover key *********
failover link stateful GigabitEthernet0/7
failover interface ip folink 192.168.254.25 255.255.255.252 standby 192.168.254.26
failover interface ip stateful 192.168.254.17 255.255.255.252 standby 192.168.254.18
monitor-interface outside
monitor-interface inside
SECONDARY
failover
failover lan unit secondary
failover lan interface folink GigabitEthernet0/6
failover key ******
failover interface ip folink 192.168.254.25 255.255.255.252 standby 192.168.254.26
Joel
02-18-2016 04:46 AM
Hi Mohd,
By default asa monitors its physical interfaces and monitoring for sub-interfaces is disabled in failover setup.
Refer following link:
http://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/failover.html#wp1073911
-RS.
Rate if it helps
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide