10-29-2012 03:19 PM - edited 02-21-2020 06:26 PM
Can I establish an endpoint of a point-to-point IPSEC VPN tunnel on an ASA 5540 Active/Standby failover pair and expect the tunnel to failover to the Standby unit in the event the Active one fails? Are there are caveats or notable behaviors in this setup/senario?
10-29-2012 04:23 PM
Hello Matt,
Yes, that is the whole purpose of the active/standby scenario for VPN on the ASA.
VPN failover only supported on active/standby ( *** No active/active support **** )
Regards,
Julio
10-29-2012 04:59 PM
Your statement of "VPN failover only supported on active/standby ( *** No active/active support **** )" is NOT true. Check this out this link: http://www.cisco.com/en/US/docs/security/asa/roadmap/asa_new_features.pdf
on page 17 it stated "Site-to-site VPN tunnels are now supported in multiple context mode". Isn't "multiple context mode" mean active/active?
10-29-2012 05:25 PM
Site-to-Site VPN in multiple context mode Site-to-site VPN tunnels are now supported in multiple context mode.
VPN is not supported on active/active, Multiple context does not mean active/active.
Regards,
Julio
10-29-2012 05:40 PM
In order to be in Active/Active, don't you have to put the ASA in multiple context mode?
Therefore, when it said "Site-to-site VPN tunnels are now supported in multiple context mode", does it mean the the ASA cluster is active/active at that point?
10-29-2012 05:51 PM
Hello,
In order to be in Active/Active, don't you have to put the ASA in multiple context mode?
Yes, that is true
But multiple-context also support active/standby This is a regular question most of the customer have...
Regards,
Julio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide