I have configured LAN failover ( Active/Standby) between two ASA 5520. In cisco site it is mentioned that the failover link between two ASA should pass through a saprate switch.
I am not able to understand what is the use of this switch in between. Cant i connect both the ASA directly using a crosscable ?
- If you need clarification, ask it in the comment box above.
- Better answers use proper spelling and grammar.
- Provide details, support with references or personal experience.
Tell us some more! Your answer needs to include more details to help people.You can't post answers that contain an email address.Please enter a valid email address.The email address entered is already associated to an account.Login to postPlease use English characters only.
Tip: The max point reward for answering a question is 15.
You can only do active/active if you're using multiple contexts. Active/active can give you some extra performance for your $ since you can pass traffic through both ASAs. Compare this to active/standby where the standby unit passes no traffic.
If you're pushing the 5510's to 80% capacity each in active/active mode, then you have one fail, now the one single ASA is oversubscribed. The oversubscription could cause connectivity issues that defeat the purpose of failover in the first place.
In the spirit of reliability go with active/standby. Seeing that you have two active core switches that would be pushing all of their traffic through a single 5510 in this case....it may be too much active/active may be the better solution.
PPPoE is not supported when failover is configured on the security appliance, or in multiple context or transparent mode. PPPoE is only supported in single, routed mode, without failover.
1. Copy the config and IOS image to a tftp server. 2. Format flash (disk0) 3. set rommon server, ip addy, and file settings. 4. tftpdnld 5. Once the system has booted to the image copy the asa image file, asdm image file, and config to flash 6. configure asdm image default location and reload
Basic Commands
pixfirewall(config)#hostname PIX
!--- Naming the PIX is optional.
PIX(config)#nameif ethernet2 fo security20
!--- Naming the interface is optional. It is recommended that you
!--- hardcode the speed/duplex.
PIX(config)#interface ethernet2 100full
!--- Bring up the interface.
PIX(config)#ip address fo 192.168.1.1 255.255.255.0
!--- Assign an IP address.
Failover Commands
PIX(config)#failover ip address fo 192.168.1.2
!--- IP address for the failover link.
PIX(config)#failover lan unit primary
!--- This unit is primary
.
PIX(config)#failover lan interface fo
!--- The 'fo' interface is used for LAN failover.
PIX(config)#failover lan key cisco
!--- The Pre-shared key.
PIX(config)#failover lan enable
!--- Enables failover.
PIX(config)#failover
!--- Start the failover process.
This message appears on the console:
LAN-based Failover: trying to contact peer
LAN-based Failover: Send hello msg and start failover monitoring
×