cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1579
Views
10
Helpful
1
Replies

Anyconnect High Availability

Hocine
Level 1
Level 1

Hi

Our network as shown in the picture below, we use any-connect for remote users. Any-connect is configured in ASA1.

I want to add ASA2 to the configuration as high availability. If the ASA1 goes down, the users will automatically use ASA2 to connect to network.

 

Is there a way I can do this High Availability between two ASAs with different ISP and public IP addresses?

Do I need to use the same IP pool in both ASAs?

 

Capture.PNG

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes - I do something like that often for our clients.

You just specify in the Anyconnect client profile a backup server. Put in the FQDN for the secondary site. If the client cannot connect on the primary it will automatically fail over to the second one. It's best to use separate pools as the ASA pairs will not know if the addresses have been assigned by the other pair. Also, your internal routing needs to know how to reach each respective pool.

VPN Backup Server ListVPN Backup Server List

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes - I do something like that often for our clients.

You just specify in the Anyconnect client profile a backup server. Put in the FQDN for the secondary site. If the client cannot connect on the primary it will automatically fail over to the second one. It's best to use separate pools as the ASA pairs will not know if the addresses have been assigned by the other pair. Also, your internal routing needs to know how to reach each respective pool.

VPN Backup Server ListVPN Backup Server List

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: