06-07-2006 08:26 AM - edited 02-21-2020 02:27 PM
Hi,
I have 2 ASA's in Active/Standby setup (context mode=single) that I am trying to configure for VPN load balancing. I have configured the appliances identically as follows:
vpn load-balancing
interface lbpublic Outside
interface lbprivate Inside
cluster key xxxxxxx
cluster ip address x.x.x.x
cluster encryption
participate
The cluster IP is on the same subnet as the outside interfaces.
Both units report themselves as masters- They are unable to see each other.
sh vpn load-balancing
Status: enabled
Role: Master
Failover: Active
Encryption: enabled
Cluster IP: x.x.x.x
Peers: 0
Can anyone please help as to why they can't see each other?
Thanks
Pradeep
06-07-2006 10:29 AM
If your running Active/Standby then you can't load balance. One is always active and the other standby. They would both have to be active to load balance. Your load balancing would be the failover. If the active failed the the secondary would take over the IP address and become active. All clients would terminate to the same IP but physically different ASA's.
Thanks,
Chad
06-07-2006 10:57 AM
Hi Chad,
Thanks for replying. I had it the way you are describing it. However, I was recently told by Cisco in this forum that VPN load balancing would work in an active/standby environment (single security context), and thus my effort to try and implement it - clearly so far it has not worked.
Thanks
Pradeep
06-13-2006 04:18 AM
Hi Chad,
Thanks for your help! I do now understand how it should work.
Thanks
Pradeep
07-24-2006 08:00 AM
Hi everybody,
So can VPN Load Balancing runs in A/S case?
07-24-2006 11:17 AM
Unfortunately, it will not work with a single A/S failover pair. You will need to have 2 failover pairs, or some combo that will give you 2 active ASA's.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide