cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2241
Views
0
Helpful
4
Replies

ASA Active/Active or VPN Cluster

bbinion80
Level 1
Level 1

Greetings,

We have two ASA's that will be used for VPN access. Initially only IPSec connections but eventually, we'll be using the SSL Web connections as well. I was curious which failover configuration would be more appropriate. Active/Active or the VPN Load Balancing Cluster. I was thinking the VPN cluster since they will not be used as firewalls but wasn't sure.

Thanks for any input.

4 Replies 4

Ivan Martinon
Level 7
Level 7

Have in mind that to have active active failover you need to have security contexts enabled on your ASA devices, and at the moment multiple firewall is enabled (contexts) VPN features are removed from the ASA.

So if I am understand what you are saying correctly, I cannot use Active/Active while using remote VPN. I'd have to use the VPN Load Balancing to utilize fault tolerance. Is this correct?

You can certainly use active/standby failover along with vpn, or you can use vpn load balance it is up to your design, what you can't use is active active failover

Yeah I was looking at Active/Standby but my boss feels that if we are using it for VPN (IPSec and SSL) he thought one unit may be doing too much and would rather have some type of load balancing in place. So it seems the VPN cluster may be the best option.