cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
392
Views
0
Helpful
2
Replies

ASA failover question

lkadlik
Level 1
Level 1

Hi,

Is it possible to have an asa pair in active/standby mode where the WAN ip addesses are on different subnets?

I had always thought they needed to be on the same lan for it to work.

Thanks

1 Accepted Solution

Accepted Solutions

Sandeep Choudhary
VIP Alumni
VIP Alumni

Hi Ikadlik,

If you want to use failover as Active / Standby then It can not be possible on diff. Subnet because for that to work, The firewall have to have L2 Adjacency.

Regards

Please rate if it helps.

View solution in original post

2 Replies 2

singhaam007
Level 3
Level 3

hello,

In ACTIVE/STANDBY mode, both IP Addresses MUST be in the same network address or you can use 2 units for this scenario. One unit primary and second one as backup.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml

But in juniper it is possible.

http://www.juniper.net/techpubs/software/junos-security/junos-security10.0/junos-security-swconfig-security/cc_deployment_scenarios.html

please rate if this helps.

thanks

Sandeep Choudhary
VIP Alumni
VIP Alumni

Hi Ikadlik,

If you want to use failover as Active / Standby then It can not be possible on diff. Subnet because for that to work, The firewall have to have L2 Adjacency.

Regards

Please rate if it helps.

Review Cisco Networking for a $25 gift card