12-16-2018 10:51 PM - edited 03-12-2019 07:10 AM
Hi All,
I have FPR2120-ASA license and with this software:
1. Cisco Adaptive Security Appliance Software Version 9.8(2)
2. Device Manager Version 7.8(2)
i am new in security section my questions are:
1. how to configure fail over between two ASAs?
2. what is the recommended image?
3.. if i want to migrate the VPN configuration from ASA5550 version 9.1(7)21, is there any tool or the same configuration i can copy ti the FPR2120 ?
Thanks,
Solved! Go to Solution.
12-23-2018 03:48 AM
Here's a link to the section in the "Cisco ASA for Firepower 2100 Series Getting Started Guide:
As it notes:
"By default, the Management 1/1, Ethernet 1/1, and Ethernet 1/2 interfaces are physically enabled for the chassis and logically enabled in the ASA configuration. To use any additional interfaces, you must enable it for the chassis using this procedure, and then later enable it in the ASA configuration."
Once you assigned and enabled the interfaces from FCM, they are available to configure and use on your ASA logical device.
12-26-2018 02:42 AM
You can use any available interface except management. The interface must be dedicated for failover purpose.
Reference:
12-17-2018 02:57 AM
I tried to configure failover on eth1/3 but the link not coming up, the link is direct connected. anyone has idea
12-17-2018 04:32 AM - edited 12-23-2018 03:44 AM
A Firepower 2100 series running an ASA image (as opposed to FTD) has two management systems. You manage the physical chassis (including assignment of physical interfaces to the ASA and enabling them) from the Firepower Chassis Manager GUI.
You then manage the ASA logical device just like a regular ASA, including when you want to build a HA pair with a mate.
12-18-2018 03:40 AM
Hi Marvin,
i am accessing via console via connect asa command, but the problem only interface eth1/1 and eth1/2 is coming up when i connected back to back cable on eth1/3-8 the port not coming up ?
is there any configuration need to do it?
12-18-2018 09:37 AM - edited 12-23-2018 03:45 AM
You need to use the Firepower Chassis Manager to assign and enable the interfaces to the ASA logical device.
12-22-2018 09:38 PM
do you have any document explain the steps ?
Thanks
12-23-2018 03:48 AM
Here's a link to the section in the "Cisco ASA for Firepower 2100 Series Getting Started Guide:
As it notes:
"By default, the Management 1/1, Ethernet 1/1, and Ethernet 1/2 interfaces are physically enabled for the chassis and logically enabled in the ASA configuration. To use any additional interfaces, you must enable it for the chassis using this procedure, and then later enable it in the ASA configuration."
Once you assigned and enabled the interfaces from FCM, they are available to configure and use on your ASA logical device.
12-25-2018 10:01 PM
Hi Marvin,
Thanks a lot for your answer, one more question can i use any interface for failover.
Thanks again.
12-26-2018 02:42 AM
You can use any available interface except management. The interface must be dedicated for failover purpose.
Reference:
12-26-2018 03:41 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: