cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
323
Views
0
Helpful
4
Replies

ASA 5520 Active standby and ssl vpn loadbalancing

v.dumont
Level 1
Level 1

I have a pair of Asa 5520 running active standby failover. Can I use both these machines in a ssl vpn loadbalancing cluster?

1 Accepted Solution

Accepted Solutions

No. When an active/standby pair is part of a VPN cluster, the standby unit is still standby - it won't be actively terminating end user sessions. Only the active (and non-failover) cluster members will be doing so.

View solution in original post

4 Replies 4

Yes, a vpn-loadbalancing-cluster member can be a standallone unit or an A/S faoilover unit. It's also allowed that some members are FO and others are standalone.

You find more information on that in the config-guide: http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/vpn_params.html#wp1048834

v.dumont
Level 1
Level 1
Could I just use the failover pair? No third asa?

No. When an active/standby pair is part of a VPN cluster, the standby unit is still standby - it won't be actively terminating end user sessions. Only the active (and non-failover) cluster members will be doing so.

And if it's more about scalability for more peers, then you can run a VPN-cluster with just two ASAs.