cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
601
Views
0
Helpful
1
Replies

ASAs and backup servers behavior

emgalanme
Level 1
Level 1

Hello, 

I have a couple of ASAs acting as VPN servers (they are in different geographical locations). The primary ASA in our list sometimes runs out of VPN licenses, so whats happening is that even though in the anyconnect xml we have both ASAs configured as backup servers, if the primary ASA runs our of licenses then the client will attempt to connect there and the connection will be rejected , hence it doesn't attempt to connect to the second server in the list.

 

VPN Load Balancing is not an option since these ASAs are in different locations (they are not L2 Adjacent on the outside interface).

 

Is there any way to overcome this?

 

Thanks!

 

Emilio

 

 

1 Reply 1

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

    Configure two different AnyConnect profiles (one connecting to primary ASA, and one contenting to secondary ASA) and distribute it between your users (50%/50%, 60%/40%, etc).

 

Regards,

Cristian Matei.