cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1472
Views
0
Helpful
6
Replies

PIX Active/Active vs Active/Standby

firestartest
Level 3
Level 3

Can anyone tell me what the main advantage of A/A is compared to A/S. For single firewall mode the failover occurs the same speed and stateful connections are passed to the standby unit. For A/A you need multiple context mode which means you cant use VPN, Dynmic Routing. I have configured both methods and testing FTP downloads when a failover occurs. I cannot see what the advantage of A/A is compared to A/S.

Any ideas?

6 Replies 6

nkhawaja
Cisco Employee
Cisco Employee

in active active failover you are utilizing both of your firewalls. traffic is flowing through both the firewall's active contexts. where as in active/standby one firewall is just sitting idle to take over once failure happens on primary

I thought in active active traffic flows through both firewalls only if you have 2 different context groups with a different context on each firewall active at the same time. I.E. customer A context active on Primary and customer B context active on Secondary.

If the firewall only needs one customer configuration then is there any point using active active?

Hi,

if I have understood correctly the active/active mechanism, you can configure two different context groups defining, somehow, two different types of traffic flows f.i., if you can.

Anyway I understood also that the only result you obtain is a static load sharing, not load balancing, and failover.

It is pretty much like having two HSRP groups.

I would like to know if anyone else agree or can explain me how it really works.

From what I have read the active active mechanism basically means you have 2 groups. 1 active on Primary and 1 active on Secondary. So if you have 4 contexts (engineering, sales, support, marketing) 2 of thses (engineering, sales) could be active on group 1 which is Primary. The other 2 (support, marketing) wouold be active on group 2 which would be the secondary firewall. This means thet group 1 is in standby state on secondary and group 2 is on standby state on primary.

That is how I understand it. Someone correct me if i'm wrong. I just cannot understand what the advantage is going to active/active mode for a single installation i.e. only one firewall context needed.

You are right.

unless you have two contexts, you will not be utilizing the active/active feature. so there doesn't seem to be any advantage there

thanks

Nadeem

khanhlq
Community Member

Does anyone deploy Active/Active configuration ?

According to description of Version 7.x, we have to buy

4 units to do A/A topo ? A/A included pair of A/S ?

rgds

Khanh

Review Cisco Networking for a $25 gift card