02-19-2025 02:49 AM
Hi,
Solved: ASA Active/Standby - ip address - Cisco Community
With reference to the above question, I know that an ASA/Firepower (FP) can, in an active/standby set up, have two IP addresses configured for Management -
interface Management1/1
management-only
nameif management
security-level 100
ip address 111.211.111.1 255.255.255.240 standby 111.211.111.2
as this is what I have at present on both an ASA and FW pair of devices, so this enables you to 'look at' both devices at the same time.
Question is 'If a standby IP address is configured on the 'Outside' interface - will this allow the standby device to receive NTP and Smart licence updates ?'
As at present my system only has a 'public ip' on the active device, so when checked we see this, active to the left, standby to the right -
Or in an Active / Standby set up you can only have one 'live' public IP address ? here's an example of my config -
interface Ethernet1/1
nameif internet
security-level 0
ip address 222.222.222.1 255.255.255.248
so could I do -
interface Ethernet1/1
nameif internet
security-level 0
ip address 222.222.222.1 255.255.255.248 standby 222.222.222.2
which would then allow both devices to be 'live' to the internet.
Advice gratefully received.
Stephen
Solved! Go to Solution.
02-19-2025 03:06 AM
Hello @Stephen Carter ,
do you have ASA or FTD ?
for ASA running ASA code the standby unit can be reached if you have the routable address for the standby unit
For ASA like 5525X with Firepower module and not managed by FMC you can be able to receive on standby outside it you have a public IP address for it.
For FTD devices I'm not sure but it is possible to make their management interfaces to route via the inside and so both units are able to reach smart license portal
Hope to help
Giuseppe
02-19-2025 03:06 AM
Hello @Stephen Carter ,
do you have ASA or FTD ?
for ASA running ASA code the standby unit can be reached if you have the routable address for the standby unit
For ASA like 5525X with Firepower module and not managed by FMC you can be able to receive on standby outside it you have a public IP address for it.
For FTD devices I'm not sure but it is possible to make their management interfaces to route via the inside and so both units are able to reach smart license portal
Hope to help
Giuseppe
02-19-2025 03:12 AM
So, yes, we have 2 pairs of ASA (5515's) - so they will be running normal ASA s/w.
and 2 pairs of Firepowers (1120's) running ASA s/w.
So in answer to your post - it's appearing that when adding a standby IP address, if there is routing the device will be able to be contacted and thus NTP and other updates would be passed to / from the devices.
02-19-2025 06:48 AM
Hello @Stephen Carter ,
the two ASA 5515 yes they can take advantage of the standby ip address
two pair of FTD running ASA SW I have no direct experience of this.
in my case I use FTDs with FDM with FTD software.
Hope to help
Giuseppe
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide