08-19-2013 07:03 PM - edited 03-11-2019 07:27 PM
Hi.. We have 2 x ASA 5520s running ver 9.0. We plan to aggregate the 2 interfaces used for LAN failover and stateful failover into a lacp PO. So both the ASAs are connected to each other directly using these 2 interfaces and then we logically make it a one PO. We then assign the PO intface an ip. Is this supported?
08-19-2013 09:08 PM
You can use any unused interface (physical, redundant, or EtherChannel) as the failover link. (Source)
That said, It would be an uncommon implementation. I almost always see them on separate physical interfaces.
08-19-2013 10:50 PM
yes, it might be uncommon, but it is recommended to reduce the probablility of split-brain scenarios (where both ASAs could become active in a worst case because of a failed FO-link). So, go for it!
Sent from Cisco Technical Support iPad App
08-20-2013 05:04 PM
Ok thnx folks... So should I use same Ips for LAN fo and stateful fo links or separate?
In other words, PO.10 can be for LAN fo and PO.11 for stateful fo , both different subnets. Or else it can be PO.10 for both sharing the same subnet?
Sent from Cisco Technical Support iPad App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide