cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1914
Views
0
Helpful
5
Replies

interface level asa failover

vishal77
Level 1
Level 1

Hello All,

 

Need to know is it mandatory to have an secondary ip addresss to an interface whose need to monitor in Active-Standby Asa failover.

 

Attaching my failover and interface configuration for your reference.

 

Device - Asa 5555-x

 

Failover On
Failover unit Primary
Failover LAN Interface: Failover GigabitEthernet0/7 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 5 of 516 maximum
MAC Address Move Notification Interval not set
Version: Ours 9.8(2), Mate 9.8(2)
Serial Number: Ours xxxxxxxxxx, Mate Unknown.

 

interface GigabitEthernet0/3

 no nameif

 no security-level

 no ip address

!

interface GigabitEthernet0/3.1

 vlan 2

 nameif user1

 security-level 100

 ip address 192.168.1.1 255.255.255.128

 policy-route route-map PBR_NEW

!

interface GigabitEthernet0/3.2

 vlan 3

 nameif user2

 security-level 100

 ip address 192.168.1.129 255.255.255.128

!

interface GigabitEthernet0/3.3

 vlan 1

 nameif user3

 security-level 100

 ip address 172.31.1.1 255.255.254.0

 

Please help

1 Accepted Solution

Accepted Solutions

It is not mandatory to have a secondary IP address on the interface.  If you do not have a secondary IP address on the interface the secondary ASA is not able to monitor the health of the primary ASA over that interface and therefore can only rely on the failover link for the primary ASA health.  This means that if there is an issue with the cable on the primary ASA interface no failover will occur as the secondary ASA sees the primary ASA as up over the failover link.

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

5 Replies 5

It is not mandatory to have a secondary IP address on the interface.  If you do not have a secondary IP address on the interface the secondary ASA is not able to monitor the health of the primary ASA over that interface and therefore can only rely on the failover link for the primary ASA health.  This means that if there is an issue with the cable on the primary ASA interface no failover will occur as the secondary ASA sees the primary ASA as up over the failover link.

--
Please remember to select a correct answer and rate helpful posts

Thanks for your help

Hello Marius,

 

If I add secondary IP address to my interface (which was not previously) for my secondary ASA able to monitor the health of the primary ASA over that interface.

Then would I need downtime for same  as I need to do configuration changes  on Active Asa or else it would no impact ?

 

 

There is no impact when adding the secondary IP address.

--
Please remember to select a correct answer and rate helpful posts

Thanks Marius
Review Cisco Networking for a $25 gift card